zoho-expense
Warn
Audited by Snyk on Apr 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a dedicated Zoho Expense integration (expense reporting/reimbursements). It explicitly lists finance-specific resources like "Reimbursements", "Cards", "Advance" and documents how to run connector actions or proxy arbitrary Zoho Expense API requests (POST/PUT/DELETE) via Membrane with authenticated access. Those capabilities can be used to create/approve/trigger reimbursements or other payment-related operations. This is a purpose-built financial integration (not a generic tool), so it grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata