alipay-payment-integration

Warn

Audited by Snyk on Aug 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The Skill explicitly instructs the agent to run curl at runtime to fetch and recursively read remote documentation (e.g., https://ideservice.alipay.com/cms/site/0izcu3), which would be parsed and used to determine answers, so remote content directly controls agent behavior.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). 此 Skill 是针对支付宝支付的接入文档,明确列出具体的支付/交易相关 API(例如 alipay.trade.pay、alipay.trade.precreate、alipay.trade.wap.pay、alipay.trade.page.pay、alipay.trade.app.pay、alipay.fund.auth.order.app.freeze、my.tradePay 等)、网关地址、SDK 与商家扣款/预授权等场景说明。该文档的主要目的是集成并发起支付/扣款/预授权等金融交易,属于明确的支付执行能力。

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:35 PM
Issues
2
Security Audit — snyk — alipay-payment-integration