my-cash-position

Warn

Audited by Snyk on Apr 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly integrates with Plaid (PLAID_CLIENT_ID / PLAID_SECRET / PLAID_ACCESS_TOKEN_...) to query Chase and Hanmi bank accounts and pull balances/transactions, and includes scripts that use the Plaid API to automatically update cash position sheets. Plaid is a banking API (listed in the core rule), and the skill is specifically designed for bank-account data access (with stored access tokens). Even though it primarily reads balances and updates Google Sheets rather than initiating payments, the presence of direct Plaid banking integration and permanent access tokens meets the "specific banking API" criterion for Direct Financial Execution authority.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 14, 2026, 12:18 AM
Issues
1