talentlms
Warn
Audited by Snyk on May 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes e-commerce and payment entities (Payment, Payment Gateway, Invoice, Subscription Plan, E-commerce Transaction, Discount Code, Subscription, Invoice Template). It exposes an integration (via Membrane actions) to interact with TalentLMS resources and run actions (membrane action run) which can be used to create/update payments, invoices, subscriptions and related transaction objects. These are specific payment-related capabilities (not generic browser or HTTP tools), so the skill grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata