lano

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill integrates with Lano, a payroll and payments platform, and explicitly exposes domain entities and actions related to payments (Employee → Payment, Contractor → Payment), invoices, company and counterparty bank accounts. It provides direct ways to run Membrane actions and proxy arbitrary requests to the Lano API (including POST/PUT methods), which enables initiating payment operations and managing bank-account-related resources. This is a specific financial integration intended to move money, not a generic tool, so it meets the Direct Financial Execution criteria.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 10:28 PM
Issues
1