pipeline-crm
Warn
Audited by Snyk on Apr 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly exposes PipelineCRM entities and actions related to money movement and financial operations (Payment, Payment Gateway, Payment Method, Refund, Transaction, Invoice, Credit/Debit Note, Journal Entry, Chart of Accounts, Purchase Order, Sales Order, etc.). It also documents using the Membrane CLI to run connector actions or proxied API requests (membrane action run / membrane request) which can execute those specific PipelineCRM endpoints. Because it provides direct, specific primitives for payments/refunds/transactions and a mechanism to invoke them, this is explicit financial execution capability (not merely a generic API or browser automation).
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata