adobe-commerce

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a specific Adobe Commerce (e‑commerce) integration exposing commerce entities like Payment, Invoice, Credit Memo, Gift Card Account and Order, and it provides Membrane actions plus a proxy that can send POST/PUT/PATCH/DELETE requests to Adobe Commerce endpoints. Those capabilities explicitly map to creating/capturing/refunding payments, issuing credit memos/gift‑card operations, and otherwise modifying financial state in the store — i.e., directly executing financial operations rather than a generic browser or HTTP tool. Therefore it meets the "Direct Financial Execution" criteria.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 08:56 AM