Stripe Connect Account Provisioner

Warn

Audited by Snyk on Mar 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly built to interact with Stripe (a payment gateway) via the Stripe API. It programmatically creates connected accounts, generates account onboarding/KYC links, requests capabilities (including card_payments and transfers), tracks payout schedules, and integrates with the Stripe Dashboard API for real-time balances in live mode. These are specific, payment-gateway operations (not generic browser or HTTP tooling) that can change account state and enable money movement on Stripe, so it constitutes direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 04:33 AM
Issues
1