xero

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose matches Xero integration, but its actual data flow sends all accounting requests and the Maton API key through a third-party gateway and control plane instead of Xero’s official API directly. That managed-proxy model may be intentional and same-org documented, but it increases trust requirements and exposes sensitive financial data to an intermediary beyond what the skill description downplays. No malicious payloads or installer abuse were found.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Sep 4, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/craftos-dev%2Fcraftbot%2Fxero%2F@09adb34fd23feb7d1313b313ed5c432cf898127c25926c28019e892c15a0466f
Security Audit — socket — xero