funraise

Warn

Audited by Snyk on Apr 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill is an integration for Funraise — a fundraising/payment platform — and explicitly exposes financial entities (Donation, Payment Method, Transaction) and the ability to run Membrane actions (membrane action run ...) with input parameters. Membrane actions are used to perform create/update operations against the Funraise API (including processing donations/transactions and managing payment methods), and Membrane handles auth so the agent can execute those actions. Because this is specifically designed to interact with a payments/donation system (i.e., move or manage money), it meets the definition of direct financial execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 12:59 AM
Issues
1
Security Audit — snyk — funraise