zeta

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated integration for Zeta, a card and expense management platform (a financial service). It provides explicit, purpose-built capabilities to list and run Zeta actions via the Membrane CLI (membrane action run ...), and to proxy arbitrary requests to the Zeta API through Membrane (membrane request ... with methods like POST/PUT/DELETE). These are specific, authenticated API-level operations against a financial system (cards, expenses, accounts) rather than a generic browser or HTTP tool, and therefore can perform direct financial actions (e.g., modify records, create transactions, control cards).

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 07:55 AM
Issues
1