ynab

Warn

Audited by Socket on Jun 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities fit YNAB management, but it relies on a non-YNAB third-party CLI that receives a sensitive financial API key and can perform consequential budget modifications. Data flow appears aligned with the stated purpose, so this is not confirmed malicious, but the external-tool trust and credential-forwarding risks make it higher than benign.

Confidence: 85%Severity: 63%
Audit Metadata
Analyzed At
Jun 29, 2026, 11:08 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fynab%2F@33a3b0412ea386f711a6eb0b7886f80c2ceb64e77163093770ee1999d64b3e65
Security Audit — socket — ynab