aiia

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an integration for Aiia, which is explicitly a payment initiation service provider (PISP) that "allows users to connect their bank accounts" and "enable account-to-account payments." The documentation shows concrete capabilities to run Membrane actions and proxy arbitrary Aiia API endpoints (including POST/DELETE/PUT) and to pass JSON input — i.e., invoke payment-related API calls. Membrane handles auth but does not remove the fact that the tool’s primary, explicit purpose is initiating and managing bank payments and financial data. This meets the definition of a specific banking/payment API capable of sending transactions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 08:57 AM