judopay
Warn
Audited by Snyk on May 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an integration for Judopay, a payment gateway, and explicitly references payment-related concepts (Payment Session, Card Details, Receipt) and uses Membrane actions to run connector-specific operations. The Membrane CLI workflow (connect, discover actions, run actions) is intended to call Judopay APIs — i.e., create/charge payment sessions, handle receipts/refunds — so this skill is specifically designed to perform payment operations (move money) rather than being a generic tool. Therefore it provides direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata