aqilla

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an integration for Aqilla, a cloud accounting system, and explicitly exposes financial entities (Payment, Receipt, Bank Account, Invoice, Remittance Advice, etc.). It provides Membrane actions and a proxy that can run arbitrary HTTP methods (POST/PUT/PATCH/DELETE) against the Aqilla API, and shows how to run actions that create/update data. Because this is a purpose-built financial/accounting integration (not a generic browser or HTTP tool) and it exposes and can modify payment/bank-related records, it grants the ability to create or modify payment/bank transaction objects — i.e., direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 08:59 AM