aloha-pos
Warn
Audited by Snyk on Mar 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an integration for Aloha POS, a point-of-sale system that explicitly manages orders and payments. It exposes connector-specific actions (via the Membrane CLI) and a proxy to arbitrary Aloha POS API endpoints with HTTP methods (POST/PUT/DELETE), which can be used to invoke payment/transaction endpoints (e.g., charge, refund, create transactions). This is a domain-specific integration (not a generic browser or HTTP tool) intended to interact with POS data and workflows, including payments — so it provides direct financial execution capability.
Audit Metadata