pp-mercury

Warn

Audited by Snyk on May 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a banking/financial CLI for Mercury with authenticated, writable operations. It includes commands that move or manage money and payment instruments: e.g. mercury-pp-cli transfer (transfer funds between accounts), cards create (issue virtual cards), recipients create (create payment recipients), AR invoice creation/cancellation, and other create/update endpoints. Agent Mode (--agent) makes these non-interactive and automatable, and workflow payment-plan provides an execute command for actual payment/transfer writes. These are specific financial execution capabilities (banking/payment operations), not generic tooling.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 8, 2026, 07:17 PM
Issues
1