elmo
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill integrates with ELMO Software, a cloud HR/payroll platform, and explicitly lists payroll-related capabilities (Payroll, Payruns, Expenses, Billing). It exposes mechanisms (Membrane "action run" and proxied HTTP requests with POST/PUT/DELETE) to invoke ELMO API actions. That combination is specifically designed to manage payroll/payrun operations (i.e., initiating payroll/billing workflows) rather than being a generic browser or HTTP tool. Because it can run API actions that create/modify payruns or billing records (and thus can be used to initiate financial transactions), it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata