roll

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated integration for Roll, a payroll platform whose primary function is managing and automating employee payments, tax filings, and compliance. The skill exposes a Membrane connector that discovers and runs Roll-specific actions (including creating and running actions via the CLI) and handles auth/credentials server-side. Because this is a domain-specific financial integration (payroll/payment execution) rather than a generic tool, it can be used to execute payroll-related transactions and therefore grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 04:04 PM
Issues
1
Security Audit — snyk — roll