enfuce

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an integration for Enfuce, a card-issuing and payment-processing platform. It explicitly exposes domain objects and operations like Cardholder, Card, Transaction, Account, Chargeback, Dispute, Settlement, and Reconciliation and uses the Membrane CLI to discover and run actions against the Enfuce connector. Those actions can be created and executed (membrane action run) and are clearly intended to manage payments and card transactions — i.e., move or manage money. This is a specific financial integration (payment gateway / card issuance), not a generic tool, so it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 12:06 AM
Issues
1
Security Audit — snyk — enfuce