Xero Automation
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed for accounting and payment operations in Xero and exposes actions that move or record money. It includes tools to create payments (XERO_CREATE_PAYMENT) with InvoiceID, AccountID, Amount, Date and Reference, and to create bank transactions (XERO_CREATE_BANK_TRANSACTION) with Type "SPEND" or "RECEIVE", BankAccountCode, LineItems, Date and Status. These are specific payment/transaction APIs (not generic tools) that can execute or record financial transfers against bank accounts and invoices, therefore granting direct financial execution authority.
Audit Metadata