billsby
Warn
Audited by Snyk on Apr 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The Billsby skill is explicitly for subscription billing and exposes payment-specific actions. The docs list and describe financial operations such as "Create One-Time Charge", "Refund" (in overview), "Get Invoice Details" (including payment status), "Cancel Subscription", and other invoice/customer/payment management actions. The Membrane CLI flow shows how to create a connection and run actions (membrane action run ...) which would execute those payment-related operations. These are specific tools to move or alter money-related state (charges, refunds, subscription billing), so this is Direct Financial Execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata