chargebee
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a specialized integration for Chargebee (a subscription billing platform) and exposes explicit billing actions such as "Refund Invoice", "Void Invoice", "Create Subscription", "Cancel Subscription", and other invoice/subscription management operations. It also allows proxying arbitrary Chargebee API requests (with authentication) via Membrane. These are specific, finance-focused actions that can initiate refunds, change billing/subscription state, and interact with invoice/payment endpoints — i.e., they can move or reverse money. Therefore it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata