whop-dev
Warn
Audited by Snyk on Sep 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow involves processing payment and membership webhooks in
rules/payments-webhooks.md, which ingest outsider-submitted webhook payloads containing untrusted free text fields.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill documentation (
whop-dev) includes references to payment integrations such as checkout flows, webhooks, payouts, and billing portals via the Whop platform SDK. These explicitly deal with financial operations, payment handling, and payouts (specifically referencingpayments-checkout.md,payments-transfers.md, etc.), qualifying as Direct Financial Execution capability.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata