built-accounting

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated integration for Built Accounting (accounting software) and explicitly exposes financial objects and actions — e.g., Payment, Invoice, Bill, Journal Entry — via Membrane actions. The Membrane CLI workflow shows how to discover and run actions (membrane action run ...) and create new actions, meaning the agent can invoke API actions that create or modify payments/invoices/financial records. Because this is a purpose-built financial/accounting integration (not a generic browser or HTTP tool) and includes explicit "Payment" capabilities that an agent can run, it meets the "specifically designed for financial operations" criterion and therefore represents direct financial execution authority risk.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 08:41 PM
Issues
1
Security Audit — snyk — built-accounting