Invoice Automation
Warn
Audited by Socket on Jun 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s stated finance purpose matches its capabilities, and the referenced accounting actions are plausible, but the real execution path is an unverified `accounting-mcp` intermediary with undisclosed provenance, data routing, and approval controls. This is not confirmed malware, but it is medium risk because it can perform consequential financial actions on sensitive billing data through a backend the user cannot verify from the skill alone.
Confidence: 83%Severity: 61%
Audit Metadata