memberful
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill integrates directly with Memberful — a subscription/payment platform — and exposes domain objects like Order, Subscription, Plan, Product, and Discount. It instructs using Membrane to run actions and proxy arbitrary HTTP requests (POST/PUT/PATCH/DELETE) against the Memberful API. That combination gives explicit, actionable API-level ability to create/modify orders and subscriptions (i.e., billing-related operations) rather than a generic browser or code tool. Because it provides direct, specific access to payment/subscription operations, it constitutes direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata