toast

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated integration with Toast, a point-of-sale system that explicitly provides payment processing. It uses a Membrane connector to discover and run Toast-specific actions and also allows proxying arbitrary requests to the Toast API (with authenticated calls and ability to POST/PATCH/etc.). Those capabilities mean the agent can invoke Toast endpoints that create charges, refunds, or otherwise move money. This is not a generic HTTP tool or browser automation — it is a connector for a payment-enabled platform and thus enables direct financial execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 10:29 PM
Issues
1