funraise

Warn

Audited by Snyk on Apr 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill integrates with Funraise — a fundraising/payment platform — and explicitly exposes financial objects (Donation, Payment Method, Transaction) and actions. It provides Membrane CLI commands to run actions (membrane action run) and to proxy arbitrary API requests (membrane request) including HTTP methods like POST/PUT/DELETE. That combination lets the agent create or modify donations, payment methods, and transactions and thus perform direct financial operations. Membrane also manages auth for those calls, making it capable of executing payment-related actions without additional user secrets.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 24, 2026, 04:27 PM
Issues
1