rydoo

Warn

Audited by Snyk on May 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Rydoo is an expense and reimbursement platform (Expense, Reimbursement, Report, Mileage) and this skill exposes a Membrane-backed integration that can discover and run connector actions (membrane action run ... --input ...). That combination is specifically targeted at a financial operational system and can be used to create/approve reimbursements or other expense-related transactions via Rydoo actions. Although it doesn’t list a specific payment gateway by name, the skill’s explicit domain (expense/reimbursement) plus Membrane’s ability to run arbitrary connector actions means it can be used to trigger financial operations (e.g., reimbursements). Therefore it represents direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 1, 2026, 12:05 AM
Issues
1
Security Audit — snyk — rydoo