elmo

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill integrates with ELMO Software, a cloud HR/payroll platform, and explicitly lists payroll-related capabilities (Payroll, Payruns, Expenses, Billing). It exposes mechanisms (Membrane "action run" and proxied HTTP requests with POST/PUT/DELETE) to invoke ELMO API actions. That combination is specifically designed to manage payroll/payrun operations (i.e., initiating payroll/billing workflows) rather than being a generic browser or HTTP tool. Because it can run API actions that create/modify payruns or billing records (and thus can be used to initiate financial transactions), it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 10:02 PM
Issues
1