Fakturownik

PassAudited by ClawScan on May 3, 2026.

Overview

Fakturownik appears to be a normal invoice generator, but it handles and may retain business tax data and includes some provenance and paid-upgrade caveats users should notice.

This skill looks broadly purpose-aligned and there is no artifact-backed evidence of exfiltration or destructive behavior. Use caution with real invoice/customer data, verify Polish tax/legal correctness yourself, confirm where any history is stored, and inspect the complete source before running or relying on paid/pro features.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Real invoices can contain tax identifiers, addresses, customer names, and pricing details that users may not want retained unexpectedly.

Why it was flagged

The skill is expected to handle invoice data, but this wording indicates buyer/seller details and invoice history may be remembered or stored.

Skill content
**Dane firmowe** — zapamiętuje dane sprzedawcy i nabywcy ... **Historia faktur** — zapisuj i zarządzaj wystawionymi fakturami
Recommendation

Before using real data, check where history is stored, how to delete it, and avoid entering sensitive customer details unless retention is acceptable.

What this means

The visible code looks purpose-aligned, but users cannot confirm every runtime behavior from the supplied text alone.

Why it was flagged

The supplied source view stops during the main function, so this review cannot fully inspect the displayed executable path even though the static scan reported no findings.

Skill content
"truncated": true
Recommendation

Review the complete source before running the Python script, especially any code that saves files, exports documents, or sends invoices.

What this means

A user may be encouraged to contact an external email address and follow a payment link outside the platform.

Why it was flagged

The skill includes an off-platform paid-upgrade/payment flow. It is disclosed, but users should verify it independently.

Skill content
**Jak wykupić?** Wyślij maila na tomaszpedzierski.infinity@wp.pl — odpowiem z linkiem do płatności.
Recommendation

Do not send money or follow external payment links unless you have independently verified the author and terms.