my-cash-position
Warn
Audited by Snyk on Apr 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly integrates with Plaid (PLAID_CLIENT_ID / PLAID_SECRET / PLAID_ACCESS_TOKEN_...) to query Chase and Hanmi bank accounts and pull balances/transactions, and includes scripts that use the Plaid API to automatically update cash position sheets. Plaid is a banking API (listed in the core rule), and the skill is specifically designed for bank-account data access (with stored access tokens). Even though it primarily reads balances and updates Google Sheets rather than initiating payments, the presence of direct Plaid banking integration and permanent access tokens meets the "specific banking API" criterion for Direct Financial Execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata