invoice-chase

Warn

Audited by Snyk on May 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to handle accounts-receivable workflows and integrates with payment gateways. It specifies pulling QuickBooks AR aging and Stripe overdue invoices, querying PayPal settled transactions (with detailed retry logic and parameters), and sending invoice reminders "via PayPal" (i.e., using PayPal's invoicing/transaction capabilities). Those are specific, finance-focused integrations with payment gateways (PayPal and optionally Stripe), not generic browser or API tooling. The presence of explicit PayPal/Stripe actions—including sending via PayPal—meets the "Payment Gateways" criterion for Direct Financial Execution even though sends require owner approval.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 13, 2026, 05:33 PM
Issues
1