b2c-hooks

Warn

Audited by Snyk on Apr 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly defines payment-related system hooks (dw.order.payment.authorize, dw.order.payment.capture, dw.order.payment.refund, validateAuthorization, reauthorize) and describes using them to perform authorization, capture, and refund operations. Those are specific, finance-focused extension points intended to execute and manage payment transactions (i.e., moving money). This meets the "Direct Financial Execution" criteria.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 15, 2026, 04:00 PM
Issues
1
Security Audit — snyk — b2c-hooks