upserve
Warn
Audited by Snyk on Apr 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an explicit integration with Upserve, a restaurant platform that exposes payment-related resources (Payment, Gift Card, Tip, Check, Order). The skill documents using Membrane actions and the Membrane proxy to call Upserve API endpoints (including POST/PUT/DELETE) with authenticated credentials. That combination is a specific, non-generic interface to a payments system and can perform money-related operations (payments, gift-card actions, tips, refunds, etc.). Therefore it provides direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata