elmo

Warn

Audited by Snyk on Apr 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an integration with ELMO Software, an HR/payroll platform, and explicitly exposes payroll-related functionality (Payroll, Payruns, Billing, Expenses). Through the Membrane CLI it can discover and run prebuilt actions (membrane action run ...) against an authenticated ELMO connection. Those actions can include running payruns or billing operations that move money. This is not a generic browser or HTTP tool — it is specifically tied to payroll/billing features and can execute actions in that domain, so it constitutes direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 06:50 PM
Issues
1
Security Audit — snyk — elmo