partnerstack
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill targets the PartnerStack API and explicitly lists financial resources — "Transaction", "Invoice", and "Payout" — and documents running actions and proxying arbitrary API requests (including POST/DELETE) via the Membrane CLI. Those combined indicate the skill can be used to initiate or manage payouts/transactions/invoices (i.e., move money) rather than being a purely generic tool. Therefore it contains explicit financial execution capabilities.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata