paycaptain
Warn
Audited by Snyk on May 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly for a payroll/financial app (PayCaptain) and exposes domain-specific capabilities like "Pay Runs", "Payments", "Deductions", and "Payslips". It instructs using the Membrane CLI to discover and run actions (membrane action run ...) against a PayCaptain connection and to create actions when needed. That combination (a payments/payroll service plus actionable API calls that can be run with input JSON) constitutes specific tools to move/manage money (e.g., run payroll or trigger payments), not a generic browser or HTTP tool. Therefore it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata