Atlas / Skills / leoyeai / Quickbooks Online

Quickbooks OnlineCAUTION

skills/leoyeai/quickbooks-online

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
1.0.0
Hosts
1 documented
License
MIT
Stars
2,160
01

Overview

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Read from source at commit 4f3b4a2a472eOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: qb-cli
description: >
  QuickBooks Online CLI tool. Manage customers, invoices, payments, bills,
  vendors, accounts, items, expenses, journal entries, deposits, transfers,
  estimates, purchase orders, and run financial reports directly via the Intuit API.
  164 commands across 29 command groups. All commands return JSON by default for agent consumption.
version: 1.0.0
metadata:
  openclaw:
    requires:
      bins:
        - docker
        - docker compose
      env:
        - QB_CLIENT_ID
        - QB_CLIENT_SECRET
        - QB_ENVIRONMENT
    primaryEnv: QB_CLIENT_ID
    emoji: "💰"
    homepage: "https://github.com/claw4business/quickbooks-online-cli"
    source: "https://github.com/claw4business/quickbooks-online-cli"
    os:
      - macos
      - linux
install:
  - run: "git clone https://github.com/claw4business/quickbooks-online-cli.git ~/skills/qb-cli"
  - run: "cp ~/skills/qb-cli/.env.example ~/skills/qb-cli/.env"
  - run: "docker compose -f ~/skills/qb-cli/docker-compose.yml build"
---

# qb-cli — QuickBooks Online CLI

Manage QuickBooks Online from the command line. Designed for both human and AI agent use. Talks directly to Intuit's QuickBooks API — no third-party proxy. 164 commands across 29 groups covering AR, AP, chart of accounts, banking, reporting, imports, reconciliation, and month-end workflows.

## Setup

The tool runs in a Docker container at `~/skills/qb-cli/`.

### Prerequisites

1. Create a QuickBooks developer account at https://developer.intuit.com
2. Create an app (Keys & OAuth section)
3. Note your Client ID and Client Secret
4. Add `http://localhost:8844/callback` as a Redirect URI

### Configuration

```bash
cp ~/skills/qb-cli/.env.example ~/skills/qb-cli/.env
# Edit .env with your Client ID and Client Secret
```

### Build (first time)

```bash
docker compose -f ~/skills/qb-cli/docker-compose.yml build
```

### Authenticate (SSH / headless)

```bash
# Step 1: Get the auth URL
~/skills/qb-cli/run.sh auth login --print-url

# Step 2: Open the URL in any browser, authorize QuickBooks
# Step 3: Copy the full redirect URL from browser address bar
# Step 4: Paste it back
~/skills/qb-cli/run.sh auth login --callback-url "http://localhost:8844/callback?code=...&realmId=..."
```

---

## CRITICAL AGENT RULES — READ BEFORE DOING ANYTHING

### Rule 1: ALWAYS Search Before Creating

**Never create a customer, vendor, or item without first searching for duplicates.**

```bash
~/skills/qb-cli/run.sh customer search "Meridian"
~/skills/qb-cli/run.sh vendor search "Acme"
```

If the search returns results, confirm with the user which one they mean. Do NOT assume.

### Rule 2: NEVER Create a Customer Without Complete Information

**You MUST have ALL of the following before creating a customer record:**
- **Display name** — Full legal name or business name
- **Company name** — The legal business entity name (if applicable)
- **Billing email address** — Required for sending invoices electronically
- **Phone number** — Primary contact phone
- **Billing address** — Full street address, city, state, and zip code

If the user says something vague like "send an invoice to Mike" or "bill Acme $500":
1. **STOP.** Do not create anything.
2. Search for the customer: `customer search "Mike"` or `customer search "Acme"`
3. If no results, ask the user for: full name, company name, billing email, phone, and billing address.
4. Only proceed once you have all fields.

### Rule 3: Confirm Before Sending Invoices/POs

- **Never send an invoice or PO by email unless the user explicitly says to send it.**
- Creating and sending are separate actions.
- Always confirm the amount, customer/vendor, and line items before creating.

### Rule 4: Verify Payments Before Applying

- Always confirm the customer, open invoices, and amounts before creating a payment.
- Include the payment reference (check #, ACH trace, wire ref) when available.
- Verify the payment total equals the sum of the per-invoice amounts.

### Rule 5: Never Delete a Bill with Applied Payments

- Before deleting a bill, check if bill-payments have been applied to it.
- Delete or void the bill-payment first, then delete the bill.

### Rule 6: Journal Entries Must Balance

- Debits must equal credits. The CLI validates this before sending.
- Always specify a memo/description for audit trail.

### Rule 7: Never Void Deposited Payments

- If a payment has been grouped into a deposit, void/delete the deposit first.
- Then void/delete the individual payment.

### Rule 8: Reconciliation Is Read-Only

- The reconcile commands are **helpers only** — they cannot mark transactions as reconciled in QB.
- Use them to identify matches, flag discrepancies, and generate reports.
- The actual reconciliation click must happen in the QuickBooks UI.

---

## Usage

All commands: `~/skills/qb-cli/run.sh [resource] [action] [options]`

Default output is JSON. Use `-o table` for human-readable or `-o csv` for export.

---

### Auth & Config

```bash
~/skills/qb-cli/run.sh auth login --print-url          # Get OAuth URL
~/skills/qb-cli/run.sh auth login --callback-url "..."  # Complete OAuth
~/skills/qb-cli/run.sh auth status                       # Check auth status
~/skills/qb-cli/run.sh auth refresh                      # Force token refresh
~/skills/qb-cli/run.sh auth logout                       # Remove tokens
~/skills/qb-cli/run.sh config init                       # Initialize config
~/skills/qb-cli/run.sh config show                       # Show config
~/skills/qb-cli/run.sh company info                      # Company details
```

---

### Customers (AR)

```bash
# Search (ALWAYS do this first!)
~/skills/qb-cli/run.sh customer search "Acme"
~/skills/qb-cli/run.sh customer search "[email protected]"
~/skills/qb-cli/run.sh customer search "555-0199"

# List
~/skills/qb-cli/run.sh customer list
~/skills/qb-cli/run.sh customer list -o table
~/skills/qb-cli/run.sh customer list --no-active-only

# CRUD
~/skills/qb-cli/run.sh customer get 123
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
SKILL.md:96
If the user says something vague like "send an invoice to Mike" or "bill Acme $500":

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__quickbooks-online.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eCAUTIONB89first audit
06

Questions

What does the Quickbooks Online skill do?

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Is Quickbooks Online safe to install?

With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Quickbooks Online access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Quickbooks Online work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement