quickbooks

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the Node Package Manager (npm) to provide the necessary tooling for Quickbooks interaction.
  • [COMMAND_EXECUTION]: The skill relies on shell commands to manage authentication, establish connections, and execute actions within the Quickbooks environment via the membrane command-line utility.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Quickbooks entities, which could contain instructions intended to influence the agent's behavior.
  • Ingestion points: Data enters the agent's context through output from the membrane action run and membrane request commands (found in SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or instructions to treat the retrieved accounting data as untrusted content.
  • Capability inventory: The skill allows the agent to read and write sensitive accounting records and perform arbitrary HTTP requests to the Quickbooks API through a proxy.
  • Sanitization: No explicit validation or filtering is mentioned for the data returned from QuickBooks before it is parsed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 09:36 PM
Security Audit — agent-trust-hub — quickbooks