snapscan

Warn

Audited by Snyk on Apr 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill is a dedicated SnapScan integration (a payment gateway) and explicitly surfaces financial actions: "Payment", "Payment Request", "Withdrawal", "Donation", "Account -> Transaction", etc. It instructs using Membrane to run connector actions (membrane action run) and to proxy arbitrary HTTP requests to SnapScan (including POST/PUT with JSON bodies and auth). Those are specific, built-for-finance APIs that can create payment requests and perform withdrawals — i.e., they are explicitly designed to move money. This meets the "Direct Financial Execution" criteria.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 23, 2026, 01:40 AM
Issues
1