shopify-admin-api

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is the Shopify Admin API, which explicitly includes payment- and billing-related resources and operations (examples in the resource list: billing, payment, refund, payout, shopify_payments, shopify_payments/transaction, applicationcharge, usagecharge, recurringapplicationcharge, applicationcredit, giftcard, balance, tendertransaction, dispute). These resources are specifically designed to create charges, process refunds/payouts, manage Shopify Payments and transactions — i.e., to move or manage money. Under the core rule (specific tools/APIs for payment gateways/transactions), this qualifies as Direct Financial Execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 03:34 AM