abra-flexibee
Warn
Audited by Snyk on Mar 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an explicit integration for ABRA FlexiBee, an accounting/ERP system, and exposes finance-specific resources (e.g., Invoice, Payment) via Membrane. The Membrane CLI instructions include running pre-built actions and proxying arbitrary API requests with HTTP methods (POST/PUT/PATCH/DELETE), which can be used to create/update/delete payment or transaction records. Because this is a purpose-built accounting/finance integration (not a generic browser or HTTP tool) and it exposes operations that can modify payment/financial records, it grants direct financial execution authority.
Audit Metadata