cybersource
Warn
Audited by Snyk on Apr 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a CyberSource payment integration. It exposes payment-specific objects (Payment Instrument Token, Customer, Payment, Subscription) and documents running Membrane actions or proxying requests directly to the CyberSource API (including POST/PUT endpoints). Those capabilities allow the agent to create payments, manage subscriptions, and perform other payment gateway operations — i.e., directly move or authorize money. This meets the definition of Direct Financial Execution.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata