rokt
Warn
Audited by Snyk on Apr 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a specific integration for the Rokt ecommerce/marketing platform and explicitly lists "Campaign" and "Campaign Budget" among its resources. It exposes concrete means to run platform actions and proxy arbitrary Rokt API endpoints via the Membrane CLI (membrane action run, membrane request), which would allow calling APIs that update campaign budgets (i.e., ad spend). That falls under "Managing Ad Spend Budgets (specifically the API to update the budget)" in the core rule. This is not a generic browser or generic HTTP tool — it's a connector to a specific marketing platform with budget management capabilities, so it qualifies as direct financial execution risk.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata