Invoice Automation

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated finance purpose matches its capabilities, and the referenced accounting actions are plausible, but the real execution path is an unverified `accounting-mcp` intermediary with undisclosed provenance, data routing, and approval controls. This is not confirmed malware, but it is medium risk because it can perform consequential financial actions on sensitive billing data through a backend the user cannot verify from the skill alone.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Jun 3, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fskills-hub%2Finvoice-automation%2F@d04bf6e3aeb579e7a6d7322f805ffc819bd1a77c
Security Audit — socket — Invoice Automation