gpc-monetization
Warn
Audited by Snyk on Mar 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly for Google Play monetization and includes commands that perform financial actions: creating/updating/deleting paid products and subscriptions, activating/deactivating base plans (affects availability for purchase), acknowledging/consuming purchases, cancelling/deferring/revoking subscriptions, and issuing refunds (e.g., "purchases orders refund "). It requires authenticated GPC credentials and supports write operations (not just read-only). These are specific payment-related APIs/functionality (in-app purchase/payment lifecycle and refunds), so it grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata