lemon-squeezy

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly about integrating Lemon Squeezy (a payment/merchant-of-record platform). It includes direct, payment-specific operations: initializing a Lemon Squeezy client with API keys, creating checkout sessions, handling payment webhooks, and managing subscription lifecycle actions (upgrades, downgrades, cancellations). Those are payment gateway functions whose primary purpose is to move/manage money/subscriptions, not generic tooling. Therefore it meets the "Direct Financial Execution" criteria.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 01:26 AM