freshbooks
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a specific Freshbooks integration for accounting workflows and explicitly exposes actions that create/manage invoices and payments (e.g., "Create Contact Payment", "Create Sales Invoice", "Create Purchase Invoice", "Create Contact Payment" and a Payment resource). It also permits proxying arbitrary calls to the Freshbooks API via Membrane (with auth), which can be used to invoke payment endpoints. These are explicit, purpose-built financial operations (creating payments/transactions), not generic tooling, so it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata