freee-api-skill

Warn

Audited by Snyk on Mar 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to interact with an accounting/invoicing/payroll API (freee). It exposes concrete API-call tools (freee_api_post/put/delete/patch/get, freee_file_upload) and domain-specific endpoints/services (accounting: deals/仕訳/取引登録, invoice: 請求書/見積書, accounting-expense-applications: 経費申請, hr: 給与/従業員情報, sm/sales: 売上/受注). Those capabilities allow creating/modifying financial records, submitting expense claims, issuing invoices, uploading receipts and registering transactions — i.e., direct financial execution/actions via the freee API. OAuth being required does not remove the fact that the skill is specifically for financial operations and can send transactional API requests. Therefore it meets the criterion for Direct Financial Execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 09:46 AM
Issues
1