openapi-esignature
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill includes explicit purchase endpoints and paid actions: e.g., "POST /certificates/namirial-otp" and "POST /certificates/namirial-automatic" to purchase signing certificates, and the Time Stamping service notes "Purchase qualified timestamps" and "buy batches, stamp a document." Those are specific APIs for executing paid transactions (purchasing services) rather than generic tooling, so the agent can initiate financial transactions on behalf of the user.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata