integrate-midtrans-payments

Warn

Audited by Snyk on Jun 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill explicitly requires fetching live Midtrans documentation at runtime (starting with https://docs.midtrans.com/llms.txt and the linked docs.midtrans.com pages) to drive its prompt/instruction decisions, so it depends on external content that directly controls agent behavior.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly and specifically about integrating with a payment gateway (Midtrans). It prescribes using Midtrans products (Snap, Core API, BI-SNAP, Payment Link, Subscriptions), creating payments, using server keys/Basic Auth, managing access tokens and notification signatures, handling callbacks/webhooks, issuing refunds (with refund_key/partnerRefundNo), and performing sandbox/live smoke tests that replay webhooks and execute provider API calls. Those capabilities are concrete, payment-provider-specific operations (creating/refunding/validating payments and managing provider credentials) rather than generic tooling. Under the Core Rule this is a Direct Financial Execution capability (payment gateway integration).

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 25, 2026, 04:16 PM
Issues
2
Security Audit — snyk — integrate-midtrans-payments