Apple Pay

Warn

Audited by Snyk on Apr 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a payment integration for Apple Pay: it describes merchant validation, payment token handling, sending tokens to a PSP or backend, and payment lifecycle operations (authorization, capture, refund/void). It names payment gateway endpoints (apple-pay-gateway.apple.com / apple-pay-gateway-cert.apple.com), references PSPs (Stripe, Adyen, Braintree), and mandates server-side handling of amounts and idempotent payment calls. This is a specific financial execution integration (payment gateway flow), not a generic tool, so it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 20, 2026, 10:44 AM
Issues
1
Security Audit — snyk — Apple Pay