clerk-auth
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill documentation explicitly references Clerk's billing/commerce APIs and specific endpoints/fields used for payments: endpoint renames from /commerce/ to /billing/ (e.g., GET /v1/billing/plans, POST /v1/me/billing/checkouts), the payment_source → payment_method field change, and other billing-related resources (plans, statements, checkouts). Those are specific, payment-related API operations (creating checkouts/managing billing), not just generic auth or HTTP tooling. Therefore it exposes direct financial execution capabilities.
Audit Metadata