invoice-generation
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and credential scope are mostly coherent for hosted invoice generation, and there is no installer or executable payload. However, it routes sensitive business and payment data to a remote API, and the specific endpoint used in the skill does not match the official documented each::sense endpoint, creating a meaningful data-flow trust inconsistency.
Confidence: 88%Severity: 58%
Audit Metadata