marqeta
Warn
Audited by Snyk on Apr 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated Marqeta integration (a card-issuing/payment platform) and exposes specific financial resources: Card, Funding Source, Transaction, Program, Offers, and direct API proxying to Marqeta via Membrane. It documents running pre-built actions and making arbitrary proxied requests (POST/PUT/DELETE) against the Marqeta API with authentication handled for you. Those capabilities explicitly enable creating/managing funding sources, issuing cards, and sending transactions — i.e., moving or controlling money. This is a specific financial integration, not a generic tool, so it qualifies as Direct Financial Execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata