api-monetization
Fail
Audited by Snyk on Aug 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The docs.stripe.com and github.com links are official/low-risk, but the absolutelyskilled.pro URLs point to an unrecognized third‑party site (possible personal skill hosting) that is not a known vendor or package registry and could be used to distribute unvetted code or installers, so they warrant caution.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). This skill explicitly describes and provides code for integrating with Stripe (payment gateway) including creating Products and Prices, creating subscriptions (stripe.subscriptions.create), and reporting usage/creating usage records (stripe.subscriptionItems.createUsageRecord) for invoicing. Those are specific payment/monetization API calls that enable moving money and automated billing—i.e., direct financial execution capability.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (medium risk: 0.50). The companion check instructs the agent to run a local
lsto inspect user skill directories and suggests installing missing skills via annpxcommand (which would execute code and modify the system), so the skill pushes actions that can change the machine state even though it doesn't request sudo or direct system-file edits.
Issues (3)
E005
CRITICALSuspicious download URL detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata