finmo

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The Finmo skill is explicitly focused on financial operations and exposes concrete payment and wallet actions. The popular actions include "Create Payin" (receive funds), "Create Payout" (send funds), "Create Wallet", "List Payouts", "List Wallets", "List Virtual Accounts", "List Payout Beneficiaries", and "List Checkouts" — all specific APIs for moving or managing money. The Membrane CLI instructions show how to run those actions programmatically (membrane action run ...), which provides direct execution capability rather than generic browsing or theoretical access. Therefore this skill grants direct financial execution authority.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 05:11 PM
Issues
1