sage-accounting

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is an explicit Sage Accounting integration (accounting/payments domain) that exposes financial actions and entities such as Payment, Receipt, Transfer, Bank Account, and Create Sales/Purchase Invoice. It provides pre-built actions and also a Membrane proxy to send arbitrary authenticated requests (POST/PUT/PATCH/DELETE) to the Sage Accounting API. Those capabilities allow the agent to create/update payments, record receipts/transfers, and otherwise perform transactional financial operations via the API — i.e., send transactions that affect financial records (and potentially initiate transfers/payments depending on the API). Under the decision logic ("is the tool's primary and explicit definition to move money?"/"Send Transaction"), this is a specific financial integration with explicit payment/transfer actions, so it meets the criteria for Direct Financial Execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 08:31 PM
Issues
1