expensify

Warn

Audited by Snyk on Apr 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated Expensify integration — a finance-focused connector for expense reports and reimbursements. It exposes Expensify-specific actions via the Membrane CLI (discoverable and runnable actions tied to a connection), and Expensify's domain includes reimbursements/payment workflows. Although no single example command explicitly says "send payment," the skill's primary, explicit purpose is interacting with financial records and workflows (including reimbursements) and can run Expensify actions that may initiate payments. This is not a generic browser or HTTP tool — it is a specific financial integration capable of executing financial operations.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 05:38 PM
Issues
1