decentro
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Yes. The skill is explicitly for a financial API (Decentro) and enumerates concrete transaction-capable actions: "Remittance → Transaction", "UPI → Collect Request / Payment", beneficiary/account operations and account aggregation. It also documents using Membrane to run actions or proxy POST/PUT requests directly to Decentro (with Membrane injecting auth). Those are specific capabilities to initiate payments and banking transactions (i.e., move money), not generic tooling. Under the Core Rule, this is a direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata