tooljet

Warn

Audited by Snyk on Mar 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill description explicitly lists Stripe as a built-in SaaS data source and the examples include a concrete action sequence that runs queries.processRefund.run() and shows a "Refund ... processed" notification. That demonstrates an explicit payment gateway integration and an example of invoking a refund (a financial transaction). Even though ToolJet is a general low-code platform, the prompt contains specific payment-related APIs/actions (Stripe, processRefund), which constitute direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 09:18 PM
Issues
1