shoprocket
Warn
Audited by Snyk on Mar 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated Shoprocket e‑commerce integration (store, orders, payment option, checkout) and exposes actionable API access via the Membrane CLI (pre-built actions and a proxy to Shoprocket endpoints). That combination lets an agent run actions or POST to Shoprocket endpoints that create/capture/refund orders or change payment settings — i.e., execute commerce/payment operations. This is not a generic browser or HTTP tool but a specific integration for an e‑commerce/payment-capable service, so it constitutes direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata