sage-payroll
Warn
Audited by Snyk on Apr 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated Sage Payroll integration (employees, payruns, reports) and exposes Membrane actions and a proxy allowing POST/PUT/PATCH calls to the Sage Payroll API. Because it is specifically designed for payroll (financial operations) and can run payrun-related actions and arbitrary requests (including write operations) with authenticated access, it provides explicit capability to initiate/pay/process payroll-related transactions. This meets the "direct financial execution" criterion.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata