biztera
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Biztera is a business-management integration that explicitly exposes finance-related objects and operations (Invoice, Payment, Refund, Transaction, Balance, Budget, etc.). The skill uses the Membrane CLI to run pre-built actions and proxy arbitrary Biztera API endpoints (with POST/PUT and JSON input). That combination lets the agent invoke Biztera endpoints to create or update payments/transactions or issue refunds—i.e., perform financial actions, not just generic browsing or querying. Under the decision logic, this is a specific integration that can send transactions/handle payments, so it represents Direct Financial Execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata