abra-flexibee

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an explicit integration for ABRA FlexiBee, an accounting/ERP system, and exposes finance-specific resources (e.g., Invoice, Payment) via Membrane. The Membrane CLI instructions include running pre-built actions and proxying arbitrary API requests with HTTP methods (POST/PUT/PATCH/DELETE), which can be used to create/update/delete payment or transaction records. Because this is a purpose-built accounting/finance integration (not a generic browser or HTTP tool) and it exposes operations that can modify payment/financial records, it grants direct financial execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 08:57 AM