lemon-squeezy
Warn
Audited by Snyk on Mar 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an explicit integration with Lemon Squeezy, a payments/Merchant-of-Record platform. It includes payment-specific APIs (e.g., createCheckout to create checkout sessions), product/pricing listing, webhook handlers for subscription events (subscription_created/updated/cancelled), invoicing/tax handling, and customer portal functionality. These are specific payment gateway capabilities (creating checkout/payment flows and managing subscription/billing state), not generic tooling, so it grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata