paystand
Warn
Audited by Snyk on Apr 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a Paystand integration (a B2B payments platform) and explicitly exposes payment-specific entities (Payment, Payment Request, Transaction, Refund, Payout Account, Payment Method, Ledger Account). It instructs using the Membrane CLI to create/connect to a Paystand connection and to discover and run actions (membrane action run ... --input '{"..."}') — i.e., invoke pre-built or custom actions that will interact with Paystand to create payments, process refunds, run transactions, and manage payout/budget-related accounts. Because this is specifically designed to operate on a payment gateway and execute payment/transaction/refund operations via API calls, it meets the criteria for Direct Financial Execution.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata