domains

Warn

Audited by Snyk on Mar 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill includes an explicit "Purchase a Domain" API (POST /api/domains/v1/portfolio) that accepts an item_id and payment_method_id and notes that a default payment method will be used if none is provided. The documentation explicitly references billing, payment methods, and ensuring sufficient funds. That endpoint performs a purchase (initiates a charge), i.e., direct financial execution rather than a purely generic operation.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 26, 2026, 02:55 PM
Issues
1
Security Audit — snyk — domains