quickbooks

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s accounting capabilities mostly match its stated QuickBooks purpose, and the CLI comes from an official npm package tied to the same vendor. The main risk is architectural: QuickBooks auth and data are mediated by Membrane, a third-party intermediary, and the skill enables write actions with real-world financial impact. This is not confirmed malware, but it carries medium security risk and should only be used with clear user approval for each state-changing action.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
May 1, 2026, 07:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fquickbooks%2F@eba408256ff95b4b11abe114ac457eff9a2a87ab
Security Audit — socket — quickbooks