currencycloud

Warn

Audited by Snyk on Apr 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill integrates with Currencycloud, a payments/currency-exchange platform, and exposes domain-specific resources and actions such as Payment, Beneficiary, Conversion, Quote, and Settlement. It documents running pre-built actions (membrane action run ... --input "{...}") and proxying raw API requests (membrane request CONNECTION_ID /path -X POST/PUT ... --json), while Membrane handles authentication and credential refresh. Those capabilities explicitly allow creating/sending payments, managing beneficiaries, performing conversions and settlements — i.e., sending financial transactions — so this is direct financial execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 25, 2026, 12:49 AM
Issues
1