revel-systems

Warn

Audited by Snyk on Mar 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly exposes payment-related operations for a POS: it lists a Payment resource and actions such as "List Payments", "Get Payment" and critically "Create Payment — Creates a new payment for an order in Revel Systems". The description also states the platform "process payments" and the Membrane proxy can be used to call Revel API endpoints (including payment/charge endpoints) with authenticated requests. These are specific, purpose-built payment operations (not generic browser automation or generic HTTP tooling), so the skill grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 02:15 PM
Issues
1