wechatpay-product-coupon
Fail
Audited by Snyk on Aug 19, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill requires retrieving and displaying example code "仅替换参数" and explicitly instructs the agent to collect needed information from the user before executing, which permits asking for and embedding API credentials or secrets verbatim into output code/requests, creating an exfiltration risk.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). 该技能文档明确针对微信支付的商品券接入,包含针对「创建商品券」「发券」「核销」「退券」等支付/券务相关接口的示例代码检索(含签名)、API 调用结构、回调与签名验签、排障手册等内容。文档的主要用途是指导调用具体支付/券务接口并处理交易相关流程,属于针对支付网关的具体执行类能力,因而具备直接金融执行的性质。
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata