snapscan
Warn
Audited by Snyk on Apr 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Yes. The skill is a dedicated SnapScan integration (a payment gateway) and explicitly surfaces financial actions: "Payment", "Payment Request", "Withdrawal", "Donation", "Account -> Transaction", etc. It instructs using Membrane to run connector actions (membrane action run) and to proxy arbitrary HTTP requests to SnapScan (including POST/PUT with JSON bodies and auth). Those are specific, built-for-finance APIs that can create payment requests and perform withdrawals — i.e., they are explicitly designed to move money. This meets the "Direct Financial Execution" criteria.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata