quickbooks

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s accounting purpose is plausible, but its actual data flow is a third-party proxy model: all QuickBooks operations and connection management run through Maton domains instead of directly against Intuit. That makes the skill higher risk than a normal API wrapper because sensitive financial data and delegated auth pass through an intermediary. No malware or installer payload is evident, but the proxy-based credential/data routing and ability to perform consequential financial actions make this a high security-risk integration.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 8, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/g-hunterai%2Fopenclaw-skills%2Fquickbooks%2F@a03e815c35a0062e07b47123bb7b17a1a88f8fce
Security Audit — socket — quickbooks