polar-migration
Warn
Audited by Snyk on May 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed for payment-platform migration and includes concrete, provider-specific API calls and actions: Polar SDK usage (create products, customers, checkouts), Stripe API calls (list/retrieve subscriptions, update cancel_at_period_end, cancel subscriptions), Paddle and Lemon Squeezy API calls, and webhook handlers that trigger actions on payment events (e.g., canceling Stripe subscriptions on order.paid). These are direct payment gateway operations and subscription management (creating/canceling/updating financial instruments), not generic automation, so it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata