mercury

Warn

Audited by Snyk on Apr 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a banking API integration (Mercury) and contains concrete endpoints and examples to move funds and manage payees: e.g., POST /account//internal-transfer (create internal transfers between accounts), POST /account//send-money (initiate money transfers), endpoints to create recipients with routing/account numbers, and other transfer-related operations. It requires an API token and provides curl commands to execute transfers — this is a specific tool to move money, not a generic capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 17, 2026, 04:44 PM
Issues
1