tribe-payments
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a Tribe Payments integration (a payment platform) and exposes payment-specific objects and actions (Transaction, Charge, Refund, Payout, Authorization, Wallet, Invoice, Settlement, etc.). It instructs use of Membrane CLI to list and run connector actions and to proxy arbitrary Tribe Payments API requests (including POST/PUT/PATCH/DELETE). Membrane handles credentials so the agent can invoke authenticated payment endpoints directly. Because the primary and explicit purpose is payment operations (including creating charges/refunds/payouts and other transaction-managing endpoints), this grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata