pci-compliance
Warn
Audited by Snyk on Aug 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill includes explicit, specific payment-gateway code (Stripe). It imports the Stripe SDK and defines server-side functions that create charges (stripe.Charge.create) and modify customer payment methods using a Stripe secret key—i.e., code to actually execute payments. This is direct financial execution capability (payment gateway API usage).
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata