launch27
Warn
Audited by Snyk on Apr 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly exposes financial resources ("Invoice", "Payment") and shows how to run actions or proxy arbitrary Launch27 API requests (POST/PUT/PATCH/DELETE) via the Membrane CLI with authenticated connections. Because it provides direct, authenticated API access to payment-related endpoints (and Membrane handles credentials), the agent can create or update payments/invoices — i.e., send transactions. This is a specific payment-capable integration rather than a purely generic tool, so it constitutes direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata