dispute-refund-audit

Warn

Audited by Snyk on Jul 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly requires a Stripe MCP connection (OAuth/restricted key) and references Stripe-specific API calls (GetMcpTools, stripe_api_search, stripe_api_details, stripe_api_read) to access disputes and refunds. These are payment-gateway integrations (Stripe) — a specific financial API rather than a generic tool — so it grants direct financial execution authority risk.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 03:32 PM
Issues
1
Security Audit — snyk — dispute-refund-audit