mercury

Warn

Audited by Snyk on Apr 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is a dedicated Mercury banking integration (via the Membrane CLI) and exposes banking-specific actions: list/get bank accounts, transactions, treasury accounts/transactions, customers, invoices, recipients, and explicit "Create Recipient" and "Create Invoice" actions. This is a Banking API integration (directly relevant per the rule "Banking APIs") and is specifically designed for financial operations (not a generic tool). Even though a "send payment" action isn't explicitly listed, the connector is clearly for bank/payment workflows and exposes create/read actions for payment recipients and invoices, indicating direct financial execution capability and risk.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 28, 2026, 11:50 PM
Issues
1