asavie

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill's API model explicitly includes financial/billing entities such as "Payment", "Invoice", "Credit Note", "Debit Note", "Tax Rate", "Currency", and "Gateway". The skill docs also show that the Membrane CLI can run actions and proxy arbitrary API requests (including POST/PUT/DELETE) against the Asavie API, which would allow creating/updating payment-related resources and interacting with payment gateways. These are specific, explicit financial operation capabilities (not just generic browser or HTTP tooling), so this qualifies as direct financial execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 08:59 AM