payment-integration
Warn
Audited by Snyk on Sep 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The workflow reads and parses incoming JSON webhook payloads via
request.json()in the SePay webhook handler (references/sepay/best-practices.md), where an external party's bank transfer content/metadata is processed.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill documentation explicitly references integrating and utilizing payment gateways such as Stripe, SePay (VietQR), Polar, Paddle, and Creem.io for payment processing, checkout flows, subscriptions, and transactions. These are specific financial execution tools and payment gateway integrations falling under Risk Category 1.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata