payment-integration

Warn

Audited by Snyk on Sep 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The workflow reads and parses incoming JSON webhook payloads via request.json() in the SePay webhook handler (references/sepay/best-practices.md), where an external party's bank transfer content/metadata is processed.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill documentation explicitly references integrating and utilizing payment gateways such as Stripe, SePay (VietQR), Polar, Paddle, and Creem.io for payment processing, checkout flows, subscriptions, and transactions. These are specific financial execution tools and payment gateway integrations falling under Risk Category 1.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 05:15 AM
Issues
2
Security Audit — snyk — payment-integration