cdr-platform

Warn

Audited by Snyk on Apr 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill exposes Membrane actions for the CDR Platform and explicitly lists a "Purchase CDR" action described as "Submit a request to purchase carbon dioxide removal." The Membrane CLI instructions show how to run actions (membrane action run ...) with JSON input, which can execute that purchase action. Because the skill defines a domain-specific "purchase" action (an explicit buying/transaction operation), it provides direct financial execution capability rather than a generic toolset.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 08:34 AM
Issues
1