firecom
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill integrates with Fire.com, which is explicitly a business account and payment automation platform ("used by businesses to manage their finances, make payments, and automate accounting tasks"). The skill exposes Fire.com-specific concepts (Account Balance, Transaction, Payment Request) and instructs use of the Membrane CLI to run connector actions and to proxy arbitrary requests to Fire.com's API (membrane action run and membrane request), including HTTP methods and JSON bodies (POST/PUT/DELETE). Those capabilities are specific to a payments/banking service and enable creating/managing payments and transactions rather than being a generic tool. Therefore this is a direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata