twikey

Warn

Audited by Snyk on Apr 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill is a specific integration for Twikey, a payment platform (like Stripe/GoCardless) focused on direct debits, invoices, subscriptions, transactions, payment requests and refunds. The doc explicitly exposes actions for creating/managing transactions, refunds, payment requests and subscriptions via the Membrane CLI (including running actions with input JSON). This is not a generic tool — its primary purpose is to move/handle money and payment operations, so it constitutes direct financial execution authority.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 02:19 PM
Issues
1
Security Audit — snyk — twikey