snapp-pay
Fail
Audited by Snyk on Aug 2, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill includes plaintext staging credentials (username, password, client_id, client_secret) and instructs forming Basic auth (base64(client_id:client_secret)), which forces the LLM to handle and could output secret values verbatim — a high exfiltration risk.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a payment gateway integration (SnappPay) and explicitly documents endpoints and flows that create payments, verify them, settle (capture) funds, revert/cancel transactions, and perform refunds/updates. These are specific financial execution operations (payment token creation, verify, settle, revert, cancel) — i.e., the ability to move/confirm/refund money — so it grants direct financial execution authority.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata