NYC

billing-sdk

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly integrates with a payment provider (Dodo Payments) and includes concrete API usage for creating checkout sessions and customer portal sessions (e.g., dodo.checkoutSessions.create, dodo.customers.createPortalSession), generated server routes for checkout/portal/webhooks, and environment variables for a live payments API key. These are specific payment gateway operations (creating payment sessions, managing subscriptions) — not generic tooling — and thus constitute direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:22 PM