apideck-rest

Warn

Audited by Snyk on Feb 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The Apideck skill explicitly exposes accounting and e-commerce connectors and resources (including "payments", "invoices", "bills", "purchase-orders", "ledger-accounts", etc.) and documents CRUD endpoints (POST/PATCH/DELETE) for those resources. That means it can be used to create/update/delete payment-related records and interact with downstream financial systems via specific connectors — functionality that goes beyond a generic HTTP tool and is specifically aimed at financial operations. Under the rule set (flag only when the skill provides specific financial/payment APIs or transaction capabilities), this skill qualifies as granting direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 23, 2026, 09:34 PM