financialforce
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated FinancialForce ERP integration (finance-specific) exposing financial entities like Payment, Receipt, Refund, Bank Account, Journal Entry, General Ledger, etc. It provides explicit action-running and proxy request capabilities (POST/PUT/PATCH/DELETE) via the Membrane CLI, allowing creation/updates of records and API calls that can create payments, issue refunds, or modify bank/accounting records. Because it is specifically designed to operate on financial objects and can execute write/transactional actions, it meets the criteria for Direct Financial Execution.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata