easypost
Warn
Audited by Snyk on Apr 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill exposes explicit transactional actions: "Buy Shipment" (purchase a shipping label) and "Refund Shipment" (request a refund), and references "Billing". Through the Membrane actions (action run) the agent can trigger these operations programmatically (including passing input JSON and running actions on a connected account). Those are concrete "send transaction"/payment/refund operations rather than generic browsing or querying, so this grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata