billing-integration

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is explicitly for billing and payment processing: it integrates Clerk Billing with Stripe, includes "connect your Stripe account", a built-in payment form with Stripe Elements, subscription creation/management, updating payment methods, invoice handling, and webhook handlers (including stripe.webhooks.constructEvent). It requires and references Stripe secret keys and test cards, and provides scripts/templates to create/cancel/modify subscriptions and handle payment events—i.e., explicit payment gateway and subscription management functionality. Therefore it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:45 AM