nuapay

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. This skill is an integration with Nuapay, a payment-processing platform (direct debit, open banking, card payments). The prompt explicitly documents actions and CLI commands to connect to a Nuapay account, run Nuapay actions (membrane action run ... ACTION_ID --json) and proxy arbitrary API requests to Nuapay (membrane request CONNECTION_ID /path/to/endpoint with HTTP methods and request bodies). Membrane handles authentication and credential refresh, so the agent can invoke authenticated endpoints that perform payments or transaction-related operations. Because this is a payment gateway integration (explicitly designed for moving money), it meets the "Direct Financial Execution" criteria.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 11:57 PM
Issues
1