finmei
Warn
Audited by Snyk on May 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly exposes payment-related actions (e.g., create-payment, update-payment, delete-payment, list-payments, get-payment). "Create Payment" in particular is a specific operation to create/record a payment for an invoice (i.e., initiate financial transactions). These are not generic tools (like a browser or generic HTTP caller) but domain-specific payment actions via the Membrane/Finmei integration, so it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata