tradeshift

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated Tradeshift integration — Tradeshift is a supply-chain payments and commerce platform and the prompt explicitly says it is used to "manage invoices and payments." The skill exposes Membrane actions and a proxy request interface that allows authenticated POST/PUT/PATCH calls to Tradeshift endpoints (including running actions with JSON input and direct API proxying), which can be used to create or execute payment-related transactions. Because the integration is specifically for a payments/commerce platform and provides the means to call payment-related API endpoints, it constitutes direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 03:34 AM
Issues
1