vendasta
Warn
Audited by Snyk on Apr 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a targeted Vendasta integration (not a generic browser or HTTP tool) and explicitly exposes financial entities and operations: Payment, Refund, Invoice, Ledger Entry, Credit Note, Billing Profile, Subscription, Plan, etc. It uses the Membrane CLI/action system to discover and run specific Vendasta actions (membrane action run ... --input ...), and Membrane manages auth so the agent can execute those actions. Those facts indicate the skill can perform concrete payment/refund and ledger operations — i.e., direct financial execution — not merely generic data access.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata