chargebee

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a specialized integration for Chargebee (a subscription billing platform) and exposes explicit billing actions such as "Refund Invoice", "Void Invoice", "Create Subscription", "Cancel Subscription", and other invoice/subscription management operations. It also allows proxying arbitrary Chargebee API requests (with authentication) via Membrane. These are specific, finance-focused actions that can initiate refunds, change billing/subscription state, and interact with invoice/payment endpoints — i.e., they can move or reverse money. Therefore it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 02:45 PM
Issues
1