invoice-chase
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to handle accounts-receivable workflows and integrates with payment gateways. It specifies pulling QuickBooks AR aging and Stripe overdue invoices, querying PayPal settled transactions (with detailed retry logic and parameters), and sending invoice reminders "via PayPal" (i.e., using PayPal's invoicing/transaction capabilities). Those are specific, finance-focused integrations with payment gateways (PayPal and optionally Stripe), not generic browser or API tooling. The presence of explicit PayPal/Stripe actions—including sending via PayPal—meets the "Payment Gateways" criterion for Direct Financial Execution even though sends require owner approval.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata