kindful

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The Kindful skill is an integration for a fundraising/CRM platform and explicitly lists financial entities and actions: "Transactions", "Payment Methods", "Recurring Donations", "Membership Transactions", "Donation Widget", "Stores/Products", etc. It also exposes Membrane actions and a proxy that can run HTTP methods (POST/PUT/PATCH/DELETE) against Kindful endpoints, which enables creating or modifying donation/transaction records and payment-related data. This is not a generic browser or HTTP tool — it is specifically designed to interact with financial transaction objects in a fundraising system, so it provides direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 03:39 PM
Issues
1