rippling-hr
Warn
Audited by Snyk on Mar 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a Rippling HR integration and explicitly lists "PayrollRuns" in its capabilities ("Manage Employees, Companies, PayrollRuns, Reports"). It provides Membrane actions and a proxy request interface (membrane action run and membrane request with arbitrary HTTP methods) plus authenticated connections — sufficient to call Rippling endpoints that create/execute payroll runs or other payment-related operations. Because it is specifically targeted at an HR/payroll platform and explicitly includes payroll-run management, it grants the ability to perform direct financial execution (e.g., triggering payroll transactions).
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata