commercetools
Warn
Audited by Snyk on Apr 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Commercetools is an e-commerce integration that explicitly exposes commerce entities such as Payment, Order, Cart, Subscription, Discount Code, etc., and the skill describes using Membrane actions to run operations against that connection (create/list/run actions, pass JSON inputs, and let Membrane handle auth). Those actions can be (and are intended to be) specific operations on commerce/payment objects (e.g., capture/refund/payments, create orders/subscriptions). This is not a generic browser or HTTP tool — it is a dedicated commerce/payment integration that can perform transactional operations that move or manage money. Under the core rule (“Is this tool's primary and explicit definition to move money?”), this qualifies as direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata