recurly

Warn

Audited by Snyk on Apr 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated Recurly integration — a subscription management and billing platform — and exposes domain-specific objects like Billing Info, Subscription, Invoice, and Transaction. It instructs use of Membrane actions and a proxy that can call Recurly API endpoints with HTTP methods (POST/PUT/PATCH/DELETE) to create or modify invoices/transactions and manage billing. This is not a generic browser or HTTP tool: it is explicitly designed to interact with a payment/billing system, giving the agent the ability to perform financial operations (create charges, manage subscriptions, invoices). Under the core rule (specific tools to move money/payment gateways), this qualifies as Direct Financial Execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 22, 2026, 09:50 AM
Issues
1