payram-bitcoin-payments

Warn

Audited by Snyk on May 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly and specifically designed for cryptocurrency financial operations. It documents on-chain Bitcoin payment acceptance, HD wallet derivation (BIP44) for generating deposit addresses, a mobile-app signing flow that approves and executes batch "sweeps" to a cold wallet, and provides API integration examples (POST to /api/v1/payment with API-Key) and webhook events (payment.successful with txHash). The skill set also lists a separate payram-payouts skill for sending crypto payouts. These are concrete tools and flows to move and settle funds (derive addresses, sign transactions, sweep to cold wallet, send payouts), not generic automation — therefore it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 15, 2026, 11:13 AM
Issues
1
Security Audit — snyk — payram-bitcoin-payments