actual-budget

Warn

Audited by Snyk on Mar 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an official Actual Budget API client explicitly designed for personal finance management and includes functions that create, update, import, and transfer transactions and interact with bank sync providers. Example capabilities that constitute direct financial execution: createAccount (with initial balance), closeAccount(transferToAccountId), importTransactions (adds transactions, including transfer payees), runBankSync (GoCardless/SimpleFIN bank/payment sync), createSchedule (scheduled outgoing/incoming amounts), and api.sync to push/pull budget changes. These are specific finance APIs for managing money and bank sync, not generic tooling, so it meets the "move money" criterion.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 8, 2026, 11:38 PM