intervals-to-freshbooks
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the business purpose is coherent, and data appears intended for official FreshBooks endpoints, but the skill forwards credentials into unverifiable local shell scripts and performs autonomous external record creation plus local persistence. This is best classified as a high-risk vulnerable workflow rather than confirmed malware.
Confidence: 86%Severity: 84%
Audit Metadata