Stripe Revenue Reconciliation Agent
Warn
Audited by Snyk on Mar 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly built around the Stripe API (stripe/stripe-node) and targets Stripe-specific financial objects (charges, refunds, disputes, payouts, payment intents, subscriptions, billing). This is a payment-gateway integration specifically designed for financial operations (reconciliation of payment records) and therefore constitutes direct financial-execution-capable tooling (Stripe is a listed payment gateway). Even if the description focuses on pulling and reconciling records, the skill’s primary and explicit domain is a payment gateway API, which meets the “payment gateways (Stripe, PayPal, etc.)” criterion for Direct Financial Execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata