pipeline-crm

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly exposes PipelineCRM entities and actions related to money movement and financial operations (Payment, Payment Gateway, Payment Method, Refund, Transaction, Invoice, Credit/Debit Note, Journal Entry, Chart of Accounts, Purchase Order, Sales Order, etc.). It also documents using the Membrane CLI to run connector actions or proxied API requests (membrane action run / membrane request) which can execute those specific PipelineCRM endpoints. Because it provides direct, specific primitives for payments/refunds/transactions and a mechanism to invoke them, this is explicit financial execution capability (not merely a generic API or browser automation).

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 07:19 AM
Issues
1