finops-patterns

Warn

Audited by Snyk on Apr 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly FinOps-focused and includes programmatic/cloud-billing APIs and resources to create and manage budgets and cost-control actions. Examples in the prompt: the Terraform google_billing_budget resource, AWS Cost Explorer anomaly monitor/subscription (aws_ce_anomaly_monitor / aws_ce_anomaly_subscription), and CI/CD Infracost integration (uses API keys and can fail PRs based on cost thresholds). These are specific, non-generic interfaces to configure cloud billing budgets/alerts and automated cost controls (i.e., programmatic budget management), which meets the criterion for direct financial execution authority.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 7, 2026, 10:30 AM
Issues
1
Security Audit — snyk — finops-patterns