xero
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose matches Xero integration, but its actual data flow sends all accounting requests and the Maton API key through a third-party gateway and control plane instead of Xero’s official API directly. That managed-proxy model may be intentional and same-org documented, but it increases trust requirements and exposes sensitive financial data to an intermediary beyond what the skill description downplays. No malicious payloads or installer abuse were found.
Confidence: 90%Severity: 58%
Audit Metadata