thrivecart
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated Thrivecart integration (a shopping-cart/payment platform) and exposes domain-specific entities and actions such as Transaction, Invoice, Subscription, Customer and "processing payments." It instructs use of Membrane actions and a proxy that supports HTTP methods (POST/PUT/DELETE) to Thrivecart API endpoints and pre-built actions (via membrane action run) — which can create/update transactions, subscriptions, invoices, and other payment-related operations. This is not a generic browser or HTTP tool: it is specifically defined to interact with a payment gateway and its financial objects, therefore it provides direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata