twilio-ai-agent-architect
Warn
Audited by Snyk on May 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly references Twilio's payment collection capability ("If AI agent collects payment info, use
<Pay>verb. Never let LLM process or log card numbers. PCI Mode is IRREVERSIBLE and account-wide.") and gives PCI/collection-related regulatory guidance (PCI DSS, FDCPA). That is a specific API/feature for handling payment transactions (collecting card data), not merely generic automation or HTTP calls. Under the rule to flag when specific payment-related APIs/functions are present, this constitutes direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata