tradogram
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Tradogram is a procurement/finance-focused integration that explicitly exposes financial entities (Payment, Bank Account, Invoice, Bill, Journal Entry, Credit/Debit Note, Budget, etc.). The skill documents how to run Membrane actions and proxy arbitrary Tradogram API endpoints (supporting POST/PUT/PATCH/DELETE) which can be used to create/update payments, bills, bank-account entries, and journal entries. Because it is a domain-specific integration for procurement/financial records and provides API-level write operations on payment/bank/accounting objects, it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata