api-transfer-pix

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a payments API for Pix transfers (create POST /v2/transfer/pix, create/send batches POST /v2/transfer/pix_batches, approve/reprove batches, cancel transfers, schedule amounts, use financial_account_uid, etc.). Those endpoints and workflows are specifically designed to initiate, approve, send, and cancel real monetary transfers to bank accounts/PIX keys — i.e., directly move money via a banking/payment API. This meets the “Direct Financial Execution” criteria.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 10:05 PM