fintoio

Warn

Audited by Snyk on Apr 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an integration with Finto.io, a financial data aggregation / banking-style API (it exposes Account and Transaction objects). It explicitly provides actions via the Membrane CLI and a generic proxy ("membrane request") that supports HTTP methods including POST/PUT/PATCH/DELETE. This is a purpose-built financial integration (banking/data aggregation) and the proxy + action-run capabilities can be used to call banking endpoints (including any endpoints that initiate transactions). Under the criteria that banking APIs/direct bank integrations are considered Direct Financial Execution capability, this skill should be flagged.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 22, 2026, 09:23 PM
Issues
1