sage-accounting
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). This skill is an explicit Sage Accounting integration (accounting/payments domain) that exposes financial actions and entities such as Payment, Receipt, Transfer, Bank Account, and Create Sales/Purchase Invoice. It provides pre-built actions and also a Membrane proxy to send arbitrary authenticated requests (POST/PUT/PATCH/DELETE) to the Sage Accounting API. Those capabilities allow the agent to create/update payments, record receipts/transfers, and otherwise perform transactional financial operations via the API — i.e., send transactions that affect financial records (and potentially initiate transfers/payments depending on the API). Under the decision logic ("is the tool's primary and explicit definition to move money?"/"Send Transaction"), this is a specific financial integration with explicit payment/transfer actions, so it meets the criteria for Direct Financial Execution.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata