pushpay
Warn
Audited by Snyk on Apr 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill integrates with Pushpay, a donation/payment platform, and exposes domain-specific financial objects and actions: Donations, Transactions, Refunds, Payment Methods, Bank Accounts, Cards, etc. It provides Membrane actions and a proxy that can run API calls (POST/PUT/DELETE) against the Pushpay API to create or modify donations/transactions and process refunds. Because the tool is explicitly designed to perform payment-related operations (including refunds and transaction management), it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata