finch

Warn

Audited by Snyk on May 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated Finch integration (a payroll/HR API) and explicitly lists financial objects like "Account -> Balance" and "Transaction". It uses the Membrane CLI to create/run connector-specific actions against a Finch connection — including arbitrary actions discoverable/creatable via Membrane (which can include payment/transaction operations). Because this skill is specifically designed to interact with a payroll/banking-style API and can run connector actions that operate on transactions and account balances, it provides the capability to execute financial operations.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 6, 2026, 08:51 PM
Issues
1
Security Audit — snyk — finch