payment-rails
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Yes. The skill is a direct integration with Payment Rails (Trolley), a payouts platform for sending money to individuals and businesses. It exposes domain-specific concepts (Recipient, Payment, Batch, Quote) and explicit operations via the Membrane CLI: creating connections, listing/ running actions, and proxying direct API requests (POST/PUT/PATCH/DELETE). The CLI + Membrane proxy automatically injects auth and supports request methods and bodies, enabling the agent to initiate outgoing payments and manage payout batches without manual credentials. This is a tool whose primary and explicit purpose is moving money.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata