xendit
Warn
Audited by Snyk on May 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated Xendit payment-gateway integration (invoices, payouts, balance) and uses Membrane to create/run actions against a Xendit connection. Xendit is explicitly for accepting payments and sending payouts, and the skill documents creating/running actions (membrane action run) that would perform operations like invoices and payouts. Membrane also manages credentials so the agent can execute authenticated payment actions. This is a specific tool whose primary purpose is moving money, not a generic interface—therefore it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata