coupa-pay

Warn

Audited by Snyk on Apr 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an integration for Coupa Pay, a payment management platform, and exposes actions and a proxy to the Coupa Pay API via the Membrane CLI. The documentation explicitly references Payment and Payment Request entities and shows how to run actions and send arbitrary POST/PUT/DELETE requests to Coupa Pay endpoints (via membrane action run and membrane request). Membrane also handles authentication and credential refresh, so the agent can invoke authenticated payment-related API calls without needing additional credentials. Because this is a specific payment integration (not a generic HTTP or browser tool) that can be used to create/submit/manage payments, it meets the definition of Direct Financial Execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 22, 2026, 01:41 AM
Issues
1