deel
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated Deel integration (a payroll/payments HRIS) with explicit actions that modify financial data and workflows. The documented actions include "Create Invoice Adjustment" (bonuses, deductions, reimbursements), "Create Contract Milestone" (milestones often tied to payments), and listing/reading paid invoices. It also exposes a Membrane proxy to call arbitrary Deel API endpoints with authenticated requests, enabling direct API operations against Deel's payment/invoice endpoints. Because these are specific, payment-related capabilities (not generic browser automation or HTTP tooling), the skill grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata