freee-api-skill
Warn
Audited by Snyk on Mar 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to interact with an accounting/invoicing/payroll API (freee). It exposes concrete API-call tools (freee_api_post/put/delete/patch/get, freee_file_upload) and domain-specific endpoints/services (accounting: deals/仕訳/取引登録, invoice: 請求書/見積書, accounting-expense-applications: 経費申請, hr: 給与/従業員情報, sm/sales: 売上/受注). Those capabilities allow creating/modifying financial records, submitting expense claims, issuing invoices, uploading receipts and registering transactions — i.e., direct financial execution/actions via the freee API. OAuth being required does not remove the fact that the skill is specifically for financial operations and can send transactional API requests. Therefore it meets the criterion for Direct Financial Execution.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata