wave-financial

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an explicit integration with Wave Financial (an accounting/banking/payments platform) and exposes domain-specific actions such as Create Invoice, Approve Invoice, Send Invoice, Create Account, List Accounts, and references Bank Account and Transaction objects. It uses Membrane to create authenticated connections and run pre-built actions against the Wave API, so an agent can perform financial/accounting operations programmatically (including interacting with bank account/transaction data and invoice lifecycle actions). This is a purpose-built financial integration rather than a generic tool, so it meets the criteria for Direct Financial Execution authority.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 11:07 PM
Issues
1