plaid-fintech

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed around Plaid, a banking API, and names finance-specific capabilities: "Link token flows, transactions sync, identity verification, Auth for ACH, balance checks, webhook handling" and includes keywords like "bank account linking, ach, payments, bank transactions." "Auth for ACH" and bank account linking are direct financial/banking integrations (banking APIs) rather than generic tools, so this grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:38 AM