revel-systems
Warn
Audited by Snyk on Mar 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly exposes payment-related operations for a POS: it lists a Payment resource and actions such as "List Payments", "Get Payment" and critically "Create Payment — Creates a new payment for an order in Revel Systems". The description also states the platform "process payments" and the Membrane proxy can be used to call Revel API endpoints (including payment/charge endpoints) with authenticated requests. These are specific, purpose-built payment operations (not generic browser automation or generic HTTP tooling), so the skill grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata