paypro
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated integration for PayPro, a payroll/payments SaaS, and explicitly exposes account/invoice/payment objects. It instructs using the Membrane CLI to run connector actions (membrane action run) and proxy arbitrary API requests (membrane request) with HTTP methods including POST/PUT/DELETE. Those capabilities allow creating or modifying payments/invoices and therefore executing financial transactions programmatically. This is specific to a payment/payroll system (not a generic automation tool), so it constitutes direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata