foxy
Warn
Audited by Snyk on Apr 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The Foxy skill integrates with an e‑commerce/transaction platform and exposes explicit actions that modify billing and transactional state. Notable actions include "Cancel Subscription" and "Update Subscription" (changing next transaction date/frequency/end date), as well as transaction-related endpoints ("Get Transaction", "List Transactions"). The Membrane proxy capability also allows sending arbitrary authenticated requests to Foxy's API, which can be used to perform payment-related operations. These are specific, non-generic financial operations (managing subscriptions and transactions), so this skill grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata