payment-integration

Warn

Audited by Snyk on Mar 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly and specifically designed for payment processing and subscription billing. It contains direct integrations with Stripe (creating Checkout sessions, PaymentIntents, customers, subscription items, reporting usage records, billing portal sessions, webhook handling, refund processing, tax calculation, etc.) and mentions RevenueCat for mobile subscriptions. Those are concrete payment gateway APIs and operations that create/authorize/record financial transactions and manage billing — not generic tooling. Therefore it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 5, 2026, 02:39 PM