helcim-automation

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is specifically for automating Helcim, a payment gateway, via a Composio "helcim" toolkit. It requires an active Helcim connection (RUBE_MANAGE_CONNECTIONS) and instructs executing discovered Helcim tools (RUBE_MULTI_EXECUTE_TOOL / RUBE_REMOTE_WORKBENCH) using schema-compliant arguments. This is not a generic browser or HTTP tool — it is explicitly designed to call Helcim toolkit operations (i.e., payment gateway functionality such as transactions, refunds, customer/payment management). Under the core rule (specific tools for payment gateways), this constitutes direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:12 PM