tellmoney

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an explicit Tell.money integration (a financial data/aggregation platform) and lists payment-specific entities like "Payment Request" and "Payment Order." It exposes Membrane actions and a proxy request capability that supports HTTP methods (POST/PUT/PATCH/DELETE) and running specific actions via membrane action run — which can be used to create or send payment orders/requests. Membrane also handles authentication, meaning the skill is explicitly intended to interact with banking/payment APIs rather than being a generic browser or HTTP tool. This meets the definition of direct financial execution (banking/payment API capability).

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 02:53 PM
Issues
1