firecom

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill integrates with Fire.com, which is explicitly a business account and payment automation platform ("used by businesses to manage their finances, make payments, and automate accounting tasks"). The skill exposes Fire.com-specific concepts (Account Balance, Transaction, Payment Request) and instructs use of the Membrane CLI to run connector actions and to proxy arbitrary requests to Fire.com's API (membrane action run and membrane request), including HTTP methods and JSON bodies (POST/PUT/DELETE). Those capabilities are specific to a payments/banking service and enable creating/managing payments and transactions rather than being a generic tool. Therefore this is a direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 09:04 PM
Issues
1