Back to skill

Security audit

Maverick Quickbooks Mcp

Security checks across malware telemetry and agentic risk

Overview

This QuickBooks skill is not malicious, but it stores OAuth tokens for sensitive accounting access in a shared local mcporter vault and has unclear runtime tool boundaries.

Install only if you intend this agent to access QuickBooks through Maverick-provisioned OAuth credentials. Confirm the actual MCP endpoint, OAuth scopes, and write permissions before use; restrict permissions on ~/.mcporter/credentials.json, pin mcporter if supply-chain control matters, and treat any create, update, delete, send, void, or sync action as a real accounting change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The skill advertises QuickBooks business-context usage, but the documented behavior includes credential seeding, persistence to a shared local vault, and use of a generic MCP wrapper rather than a narrowly scoped QuickBooks implementation. That mismatch is security-relevant because operators may approve or invoke the skill expecting read/write accounting actions only, while it also handles OAuth secrets and shared credential state, increasing the chance of unintended token exposure, privilege creep, or misuse of generic tooling.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.