square-automation
Automate Square Payments and Invoices
Square operations can require many careful API steps across payments, orders, invoices, and locations. This skill provides structured Rube MCP workflows with schema checks and safety notes.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "square-automation" from https://skillstore.io/skills/sickn33-square-automation.md and its manifest at https://skillstore.io/api/skills/sickn33-square-automation/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "square-automation". Show recent payments for the Downtown location.
Expected outcome:
The skill would resolve the Downtown location ID, list recent payments, and summarize payment dates, statuses, amounts, and pagination status.
Using "square-automation". Cancel the unpaid invoice for this customer.
Expected outcome:
The skill would retrieve the invoice, verify it is eligible for cancellation, confirm the invoice ID and version, then request final approval.
Using "square-automation". Find open orders from yesterday.
Expected outcome:
The skill would list locations, search orders with a date filter, and provide matching order IDs with state and follow-up options.
Security Audit
Medium RiskMost static external command and reconnaissance findings are false positives caused by Markdown code formatting and Square object identifiers. The audit confirms a low-risk external MCP endpoint and adds contextual findings for third-party Square OAuth access and financially destructive Square operations. No prompt injection language was found in SKILL.md.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (48)
🌐 Network access (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-square-automation/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-square-automation?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-square-automation?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-square-automation/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-square-automation.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
sickn33. (2026). square-automation security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-square-automation/audits/4BibTeX citation
@techreport{sickn33-sickn33-square-automation-2026,
author = {sickn33},
title = {square-automation security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/sickn33-square-automation/audits/4},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "square-automation security audit report (audit version 4)"
version: "unspecified"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-07"
url: "https://skillstore.io/skills/sickn33-square-automation/audits/4"
identifiers:
- type: other
value: "skillstore:sickn33-square-automation:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Monitor Recent Payments
Review payment status, filter by dates or locations, and identify pending payments that may need action.
Resolve Order Updates
Find customer orders, retrieve full details, and update records with the current Square version value.
Review and Cancel Invoices
List invoices for a location, inspect invoice details, and cancel eligible unpaid invoices after confirmation.
Try These Prompts
Search current Rube tools for Square schemas, confirm my Square connection is active, then list all business locations with names, IDs, status, and timezone.
Search current Square payment tools, then list payments for the last seven days at the selected location. Summarize status, amount, and next actions.
Resolve the location ID, search Square orders for my customer criteria, retrieve the best match, and explain any update requirements before changing it.
Search current invoice tools, list unpaid invoices for a location, flag stale invoices, and ask for confirmation before any cancellation.
Best Practices
- Search Rube tools at the start of each session because schemas can change.
- Confirm Square connection status and business location before running any action.
- Preview target IDs, versions, amounts, and customer impact before update or cancel operations.
Avoid
- Do not cancel payments or invoices from a partial match or unclear user request.
- Do not reuse stale pagination cursors or version values across separate sessions.
- Do not assume location names are unique without checking returned location IDs.