fidel
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly integrates with Fidel, a named financial infrastructure API for connecting to users' credit and debit cards and accessing card transaction/authorization data. It exposes Membrane CLI actions and a proxy that can call Fidel endpoints (including POST/DELETE methods) and manage connections/auth — i.e., a purpose-built financial API integration (similar class to Plaid/banking APIs listed in the rule). This is a specific financial integration rather than a generic tool, so it meets the criteria for Direct Financial Execution risk.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata