billing-integration

Warn

Audited by Snyk on May 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to integrate a billing/payment provider (Credyt) into an application: it requires server-side API key setup, creating Credyt customers and subscriptions, handling pending payment flows (redirect_url, return_url, failure_url), creating billing portal/top-up sessions, checking wallet balances and gating actions, and listening for payment-related webhooks (subscription.activated). Those are specific payment/billing API operations (including hosted Stripe flows, portal sessions, balance/top-up), not generic tooling. This clearly grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 13, 2026, 04:11 PM
Issues
1