procountor-fi

Warn

Audited by Snyk on Apr 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill is explicitly designed to interact with accounting and payment entities in Procountor via Apideck's Accounting unified API. The documentation states “✅ Full CRUD on invoices, bills, payments” and instructs the agent to “create an invoice in Procountor” and “reconcile payments in Procountor.” It also exposes a Proxy API that can call arbitrary Procountor endpoints (Apideck injects auth headers), enabling downstream payment-related endpoints to be invoked. These are specific, purpose-built payment/banking/accounting API operations (not generic browser automation or HTTP callers), so the skill grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 27, 2026, 05:58 PM
Issues
1
Security Audit — snyk — procountor-fi