api-monetization

Fail

Audited by Snyk on Aug 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The docs.stripe.com and github.com links are official/low-risk, but the absolutelyskilled.pro URLs point to an unrecognized third‑party site (possible personal skill hosting) that is not a known vendor or package registry and could be used to distribute unvetted code or installers, so they warrant caution.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill explicitly describes and provides code for integrating with Stripe (payment gateway) including creating Products and Prices, creating subscriptions (stripe.subscriptions.create), and reporting usage/creating usage records (stripe.subscriptionItems.createUsageRecord) for invoicing. Those are specific payment/monetization API calls that enable moving money and automated billing—i.e., direct financial execution capability.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.50). The companion check instructs the agent to run a local ls to inspect user skill directories and suggests installing missing skills via an npx command (which would execute code and modify the system), so the skill pushes actions that can change the machine state even though it doesn't request sudo or direct system-file edits.

Issues (3)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 10, 2026, 02:06 PM
Issues
3
Security Audit — snyk — api-monetization