xero
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the trust model is not. The skill reads a local 1Password service-account token, injects Xero secrets, and executes a private personal repo plus npm dependencies with those credentials; that is disproportionate and creates a high credential-forwarding and supply-chain risk despite otherwise purposeful instructions.
Confidence: 90%Severity: 86%
Audit Metadata