openydt-monthticket
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). 该 skill 明确包含用于发起/修改金钱相关操作的专用命令和参数(不是泛化的浏览器或通用 HTTP 工具),其主要功能包含创建订单、开通/续费/月票扣减、退费/取消订单等可直接影响账务的操作。例:openydt ticket add-online-month-ticket(含 originPrice/favorPrice/payMode/payOrigin/billCode/thirdpartyIdentify 等)、renew-online-vip-ticket(续费)、cancel-online-vip-ticket(退费,含 refundPrice)、deduct-month-ticket-config(名额/扣减并含 thirdpartyBillCode)以及按类型批量取消等写命令。这些命令接受金额、账单号、退款金额等参数并会实际变更账务状态,属于专门用于财务/支付流程的域操作,因此具备直接金融执行能力。
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (2)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata