Skip to main content

navan-core-workflow-b

Automates Navan expense reporting and transaction synchronization with ERP systems for efficient financial management.

Install this skill

or
21/100

Security score

The navan-core-workflow-b skill was audited on May 23, 2026 and we found 23 security issues across 3 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 51

Template literal with variable interpolation in command context

SourceSKILL.md
51const tokenRes = await fetch(`${process.env.NAVAN_BASE_URL}/ta-auth/oauth/token`, {
medium line 61

Template literal with variable interpolation in command context

SourceSKILL.md
61const headers = { Authorization: `Bearer ${access_token}` };
medium line 71

Template literal with variable interpolation in command context

SourceSKILL.md
71`${process.env.NAVAN_BASE_URL}/v1/bookings` +
medium line 78

Template literal with variable interpolation in command context

SourceSKILL.md
78console.log(`ID: ${txn.transaction_id}`);
medium line 79

Template literal with variable interpolation in command context

SourceSKILL.md
79console.log(` Employee: ${txn.employee_name} (${txn.employee_id})`);
medium line 80

Template literal with variable interpolation in command context

SourceSKILL.md
80console.log(` Amount: ${txn.currency} ${txn.amount}`);
medium line 81

Template literal with variable interpolation in command context

SourceSKILL.md
81console.log(` Category: ${txn.category}`);
medium line 82

Template literal with variable interpolation in command context

SourceSKILL.md
82console.log(` Status: ${txn.approval_status}`);
medium line 83

Template literal with variable interpolation in command context

SourceSKILL.md
83console.log(` Merchant: ${txn.merchant_name}`);
medium line 114

Template literal with variable interpolation in command context

SourceSKILL.md
114console.log(`${txn.transaction_id}: $${txn.amount} -> route to ${approver}`);
medium line 139

Template literal with variable interpolation in command context

SourceSKILL.md
139console.log(`${txn.transaction_id}: ${txn.category} -> GL ${gl}`);
medium line 155

Template literal with variable interpolation in command context

SourceSKILL.md
155memo: `Navan: ${txn.merchant_name} - ${txn.employee_name}`,
medium line 167

Template literal with variable interpolation in command context

SourceSKILL.md
167console.log(`Prepared ${journalEntries.length} journal entries for NetSuite sync`);
medium line 194

Template literal with variable interpolation in command context

SourceSKILL.md
194```python
low line 51

Access to .env file

SourceSKILL.md
51const tokenRes = await fetch(`${process.env.NAVAN_BASE_URL}/ta-auth/oauth/token`, {
low line 56

Access to .env file

SourceSKILL.md
56client_id: process.env.NAVAN_CLIENT_ID!,
low line 57

Access to .env file

SourceSKILL.md
57client_secret: process.env.NAVAN_CLIENT_SECRET!,
low line 71

Access to .env file

SourceSKILL.md
71`${process.env.NAVAN_BASE_URL}/v1/bookings` +
low line 42

External URL reference

SourceSKILL.md
421. Navigate to [Navan Help Center](https://app.navan.com/app/helpcenter)
low line 199

External URL reference

SourceSKILL.md
199base_url = os.environ.get('NAVAN_BASE_URL', 'https://api.navan.com')
low line 224

External URL reference

SourceSKILL.md
224- [Navan Help Center](https://app.navan.com/app/helpcenter) — Support and documentation
low line 225

External URL reference

SourceSKILL.md
225- [Navan Integrations](https://navan.com/integrations) — NetSuite, Sage Intacct, Xero, QuickBooks connectors
low line 226

External URL reference

SourceSKILL.md
226- [Booking Data Integration](https://app.navan.com/app/helpcenter/articles/travel/admin/other-integrations/booking-data-integration) — Data export configuration
Scanned on May 23, 2026
View Security Dashboard
Installation guide →