funraise
Warn
Audited by Snyk on Apr 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Yes. The skill integrates with Funraise — a fundraising/payment platform — and explicitly exposes financial objects (Donation, Payment Method, Transaction) and actions. It provides Membrane CLI commands to run actions (membrane action run) and to proxy arbitrary API requests (membrane request) including HTTP methods like POST/PUT/DELETE. That combination lets the agent create or modify donations, payment methods, and transactions and thus perform direct financial operations. Membrane also manages auth for those calls, making it capable of executing payment-related actions without additional user secrets.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata