accounts-payable-agent

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Accounts Payable Agent footprint is largely coherent with its stated purpose: autonomous payment processing with idempotency, multi-rail routing, and audit logging. However, there are security-conscious concerns: API keys are stored in config, logs may expose sensitive data, and reliance on an external MCP binary introduces supply-chain risk. The install path uses official npm package registry and documented endpoints, which is acceptable. Overall, the risk is MEDIUM (suspicious-to-moderate) with actionable mitigations: enforce secret management, minimize logged data, implement least-privilege API keys, and audit the MCP integration for credential handling and data exposure. In doubt, treat as SUSPICIOUS until stronger secret-management controls are demonstrated.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:46 AM
Package URL
pkg:socket/skills-sh/Dev-Dennis-040%2Fopenclaw-agency-skills%2Faccounts-payable-agent%2F@d370d104c365685f805ea8d40b37d65fac14d556
Security Audit — socket — accounts-payable-agent