worldline

Warn

Audited by Snyk on Apr 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an explicit integration with a payment processor (Worldline). It exposes domain-specific entities (Merchant, Transaction, Report) and documents running pre-built actions and proxying arbitrary Worldline API requests (membrane action run and membrane request) including POST/PUT/DELETE with JSON bodies. Because Worldline is a payment gateway and the skill’s primary purpose is interacting with payment/transaction APIs (and Membrane handles authentication so the agent can invoke those APIs), this is specifically designed for financial operations capable of sending payment/transaction requests. Therefore it meets the "Direct Financial Execution" criterion.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 3, 2026, 06:44 AM
Issues
1