jobber
Warn
Audited by Snyk on Apr 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly exposes Jobber entities and actions related to money movement (Payments, Refund, Transaction, Transfer, Deposit, Payment Method, Chargebee Subscription, Invoices). It uses a connector (Membrane CLI) to run actions against Jobber (including creating/running actions), which implies the agent can create or modify payment/transaction records (e.g., create payments or refunds). This is not a generic browser or HTTP tool — it’s a specific integration that can perform financial operations, so it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata