zoho-books
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated Zoho Books accounting integration and explicitly exposes accounting/payment actions (Invoice, Invoice Payment, Customer Payment, Bill Payment, Bill, Journal Entry, Recurring Invoice, etc.). It also provides a proxy to call Zoho Books API endpoints (via Membrane) with arbitrary HTTP methods and JSON bodies, and pre-built actions can be run to create or modify payments and transactions. These are specific, purpose-built financial operations (creating/recording payments, bills, invoices, and transactions), not generic tooling. Therefore it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata