saas-transformer

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly orchestrates billing and subscription integration with payment providers (Stripe, PayPal, Paddle, etc.), includes schema fields for stripe_customer_id/stripe_subscription_id, implements Stripe Checkout/checkout flow, webhook handling with signature verification and idempotency, customer billing portal, trial/dunning management, and a pre-launch item requiring "Stripe in live mode". These are specific, dedicated financial integration capabilities (payment gateways/subscription management), not generic tooling — therefore it grants direct financial execution authority.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 02:51 PM
Issues
1
Security Audit — snyk — saas-transformer