softledger

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated integration for SoftLedger, an accounting/financial system, and explicitly exposes financial entities and operations (Payment, Deposit, Invoice, Bill, Payroll, Bank Rule, etc.). It provides Membrane-backed actions and a proxied HTTP request interface (with POST/PUT/PATCH/DELETE) that automatically handles authentication, enabling the agent to create or modify payment/deposit/billing records and otherwise perform financial operations via the SoftLedger API. Because this is specifically designed for financial/accounting operations and enables sending requests that can create or alter monetary transactions/records, it meets the criteria for Direct Financial Execution authority.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 09:32 AM
Issues
1