cancel-and-restock
Warn
Audited by Snyk on Apr 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly performs order cancellations via a Shopify GraphQL mutation (orderCancel) that includes a refund parameter and states "If
refund: true, any captured payment is automatically refunded." This is a specific, built-in capability to move money (issue refunds) through the platform rather than a generic UI or API caller, so it constitutes direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata