finch

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated Finch integration (a payroll/HR API) that exposes account balance and transaction functionality and lets the agent run Finch actions or proxy arbitrary Finch API requests (including POST/PATCH/DELETE) via the Membrane CLI. This is a specific financial/payroll integration rather than a generic tool, and it provides the means to create or run transaction-related endpoints (i.e., to move money). Therefore it constitutes direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 08:12 PM
Issues
1