employment-hero

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill integrates with Employment Hero, an HR/payroll platform, and exposes payroll-related entities and actions (e.g., "Payrun", "Expense Claim", "Get Employee Bank Accounts"). It uses Membrane to discover and run connector actions, and Membrane actions can be created or invoked to perform operations on the Employment Hero API. Because Employment Hero is explicitly a payroll/payments platform and the skill surfaces payrun and bank-account operations—capable of triggering payroll/payout workflows—this is a specific financial-execution integration rather than a generic tool. Therefore it can be used to move money (run payroll/payouts).

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 12:51 PM
Issues
1