billing-integration
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to integrate a billing/payment provider (Credyt) into an application: it requires server-side API key setup, creating Credyt customers and subscriptions, handling pending payment flows (redirect_url, return_url, failure_url), creating billing portal/top-up sessions, checking wallet balances and gating actions, and listening for payment-related webhooks (subscription.activated). Those are specific payment/billing API operations (including hosted Stripe flows, portal sessions, balance/top-up), not generic tooling. This clearly grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata