coupa-pay
Warn
Audited by Snyk on Apr 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an integration specifically for "Coupa Pay" — a payment management product — and explicitly references payment objects ("Payment Request", "Payment") and managing/automating payment workflows. It uses the Membrane connector model to create/run actions against the Coupa Pay connection; those actions can be discovered, created, and executed via membrane action run with arbitrary input JSON. Because the integration's primary domain is payments and it provides primitives to invoke Coupa Pay actions (which can include creating/sending payments), this is explicit financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata