webexpenses

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill connects to Webexpenses, a dedicated expense-management system whose core functionality includes "submitting, approving, and reimbursing employee expenses." The integration exposes Membrane actions and a proxied request interface (supports POST/PUT/DELETE and arbitrary endpoint calls) tied specifically to the Webexpenses API and manages auth for that connection. Because it is a specific financial application (expense reimbursement) and provides the ability to call actionable endpoints (not just generic browsing or generic HTTP), it can be used to initiate reimbursements/payments and therefore grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 08:12 PM
Issues
1