paycaptain
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an integration for PayCaptain, a payroll/financial app, and explicitly exposes Pay Runs, Payments, Deductions, Employee Records and related operations. It provides mechanisms to run pre-built actions (membrane action run) and to proxy arbitrary API requests (membrane request) to the PayCaptain API with HTTP methods including POST/PUT/PATCH/DELETE. Membrane also handles authentication for these calls, which means the skill can be used to create or modify payment-related resources (e.g., initiate pay runs or payments). This is not a generic browser or HTTP tool — it is specifically designed to interact with a finance/payments system and therefore can directly execute financial operations.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata