kindful

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill integrates with Kindful, a CRM built around donations and donor financial records, and exposes domain-specific objects and actions such as "Transactions", "Payment Methods", "Recurring Donations", "Membership Transactions", "Donation Widget", "Stores" and "Products". It uses Membrane to discover and run connector actions (e.g., create/run actions for a connection), which in a Kindful context commonly include creating/updating financial transactions and payment methods—i.e., actions whose primary purpose is to record or execute payments/donations. This is not a generic browser or HTTP tool: it is a specialized integration for fundraising/payment-related operations, so it constitutes direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 01:41 PM
Issues
1
Security Audit — snyk — kindful