rokt

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a specific integration for the Rokt ecommerce/marketing platform and explicitly lists "Campaign" and "Campaign Budget" among its resources. It exposes concrete means to run platform actions and proxy arbitrary Rokt API endpoints via the Membrane CLI (membrane action run, membrane request), which would allow calling APIs that update campaign budgets (i.e., ad spend). That falls under "Managing Ad Spend Budgets (specifically the API to update the budget)" in the core rule. This is not a generic browser or generic HTTP tool — it's a connector to a specific marketing platform with budget management capabilities, so it qualifies as direct financial execution risk.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 05:34 PM
Issues
1