bedrock-agentcore-multi-agent
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill defines domain-specific agents (billing/returns) with explicit financial-action functions and flows. Examples include a billing collaborator for "payment issues, invoices, and account billing", returns-agent tools such as process_refund(order_id)
- "Issue refund", and descriptions of the Billing Agent handling "payment update" (changing payment method). Those are explicit, domain-specific operations to move or modify money/transactions (refunds/payment updates), not generic tooling. Therefore it grants direct financial execution capability.
Audit Metadata