beeswax

Warn

Audited by Snyk on Mar 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The Beeswax skill is an integration for a programmatic advertising platform (a DSP) and exposes actions that create and update campaigns and line items. The documented "Popular actions" explicitly list Create/Update Campaign and Create/Update Line Item, and the Membrane proxy lets you send arbitrary POST/PUT requests to the Beeswax API. Those actions are the API surface used to set or change ad budgets/bids and thereby control ad spend. Because this is a targeted ad-buying integration (not a generic browser or HTTP tool) and it exposes update/create operations that can change budget/spend, it constitutes direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 12, 2026, 05:01 AM
Issues
1