asavie
Warn
Audited by Snyk on Mar 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill's API model explicitly includes financial/billing entities such as "Payment", "Invoice", "Credit Note", "Debit Note", "Tax Rate", "Currency", and "Gateway". The skill docs also show that the Membrane CLI can run actions and proxy arbitrary API requests (including POST/PUT/DELETE) against the Asavie API, which would allow creating/updating payment-related resources and interacting with payment gateways. These are specific, explicit financial operation capabilities (not just generic browser or HTTP tooling), so this qualifies as direct financial execution authority.
Audit Metadata