uniweb
Warn
Audited by Snyk on Jul 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a payment integration and exposes concrete, money-moving APIs and CLI commands. The documentation and SDK surface include methods and commands to create payments (await uniweb.payments.create), void payments, create refunds (await uniweb.refunds.create / uniweb payment refund), and initiate payouts / manage bank accounts (uniweb payout create, uniweb bank add, payout.*). It also documents key scopes like payments.write, refunds.create, payouts.create and wallet/bank account management. These are specific financial execution capabilities (payment gateway, refunds, payouts), not generic tooling.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata