z-api
Warn
Audited by Snyk on Apr 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly lists financial resources (Invoices, Payments, Payment Details) as first-class parts of the connector and documents how to run actions or proxy POST/PUT requests via the Membrane CLI against Z-API endpoints. That combination indicates the connector can be used to create or modify payment-related records and issue transactional API calls (e.g., sending POST requests to payment endpoints). This is not mere generic browser automation or a vague API caller — it is a specific integration exposing payment/invoice functionality, so it affords direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata