
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@mindstone/mcp-server-quickbooks
Advanced tools
QuickBooks Online MCP server for Model Context Protocol hosts — invoices, bills, customers, vendors, accounts
QuickBooks Online MCP server for Model Context Protocol hosts. Manage invoices, bills, customers, vendors, employees, and accounts in QuickBooks Online through a standardised MCP interface.
QUICKBOOKS_REFRESH_TOKEN)STATUS.jsonStarting with version 0.3.0, every QuickBooks-mutating tool
(create_quickbooks_invoice, create_quickbooks_bill,
create_quickbooks_customer, create_quickbooks_vendor,
create_quickbooks_estimate, send_quickbooks_invoice_email,
update_quickbooks_invoice, update_quickbooks_customer,
update_quickbooks_vendor) is secure-by-default:
the tool refuses to execute and returns a structured error unless the host
sets QB_ALLOW_PROD_WRITES=1 in the environment. Read-only tools
(list_*, get_*, query_*, download_*, configure_quickbooks) are unaffected.
This is a deliberate guard-rail to prevent an LLM agent from accidentally writing to a real QuickBooks production company. Hosts that have integrated 0.2.x and rely on those mutating tools must opt in by setting the environment variable on the next upgrade.
To preserve the previous (write-enabled) behaviour, add QB_ALLOW_PROD_WRITES=1
to the env block of your host configuration alongside the existing
QUICKBOOKS_* variables. Without it, the mutating tools will return:
{
"ok": false,
"error": "QuickBooks mutating tools refuse to run unless QB_ALLOW_PROD_WRITES=1 is set. ...",
"code": "QB_ALLOW_PROD_WRITES_REQUIRED"
}
We strongly recommend keeping the gate closed in any host where the LLM should not be able to issue production writes (sandbox, staging, demo, or read-only analyst workflows). Set the variable only in environments where QuickBooks writes are an intentional capability.
After clicking the button, your host will prompt you to fill: QUICKBOOKS_CLIENT_ID, QUICKBOOKS_CLIENT_SECRET, QUICKBOOKS_REFRESH_TOKEN, QUICKBOOKS_REALM_ID, QUICKBOOKS_ENVIRONMENT.
{
"mcpServers": {
"QuickBooks Online": {
"command": "npx",
"args": [
"-y",
"@mindstone/mcp-server-quickbooks"
],
"env": {
"QUICKBOOKS_CLIENT_ID": "",
"QUICKBOOKS_CLIENT_SECRET": "",
"QUICKBOOKS_REFRESH_TOKEN": "",
"QUICKBOOKS_REALM_ID": "",
"QUICKBOOKS_ENVIRONMENT": "production"
}
}
}
}
cd <path-to-repo>/connectors/quickbooks
npm install
npm run build
npx -y @mindstone/mcp-server-quickbooks
node dist/index.js
QUICKBOOKS_CLIENT_ID — Intuit Developer app client IDQUICKBOOKS_CLIENT_SECRET — Intuit Developer app client secretQUICKBOOKS_REFRESH_TOKEN — OAuth 2.0 refresh tokenQUICKBOOKS_REALM_ID — QuickBooks company (realm) IDQUICKBOOKS_ENVIRONMENT — sandbox or production (default: production)QB_ALLOW_PROD_WRITES — set to exactly 1 to enable the
mutating tools (every create_*, update_*, and
send_quickbooks_invoice_email). Any other
value (unset, empty, true, yes, 0, …) keeps the secure-by-default
gate closed and the mutating tools refuse to run. Read-only tools are
unaffected. Required since 0.3.0 to preserve 0.2.x write behaviour.MCP_HOST_BRIDGE_STATE — optional path to a host bridge state file used for credential managementMINDSTONE_REBEL_BRIDGE_STATE — backwards-compatible alias for MCP_HOST_BRIDGE_STATE{
"mcpServers": {
"QuickBooks": {
"command": "npx",
"args": ["-y", "@mindstone/mcp-server-quickbooks"],
"env": {
"QUICKBOOKS_CLIENT_ID": "your-client-id",
"QUICKBOOKS_CLIENT_SECRET": "your-client-secret",
"QUICKBOOKS_REFRESH_TOKEN": "your-refresh-token",
"QUICKBOOKS_REALM_ID": "your-realm-id"
}
}
}
}
{
"mcpServers": {
"QuickBooks": {
"command": "node",
"args": ["<path-to-repo>/connectors/quickbooks/dist/index.js"],
"env": {
"QUICKBOOKS_CLIENT_ID": "your-client-id",
"QUICKBOOKS_CLIENT_SECRET": "your-client-secret",
"QUICKBOOKS_REFRESH_TOKEN": "your-refresh-token",
"QUICKBOOKS_REALM_ID": "your-realm-id"
}
}
}
}
configure_quickbooks — Configure QuickBooks Online OAuth credentialsquery_quickbooks — Run a QuickBooks query using QuickBooks Query Languageget_quickbooks_entity — Get a single entity by type and IDget_quickbooks_report — Run a financial report (ProfitAndLoss, BalanceSheet, CashFlow, AgedReceivables, AgedPayables)list_quickbooks_customers — List customerscreate_quickbooks_customer — Create a new customerupdate_quickbooks_customer — Sparse-update a customer (deactivate with active: false)list_quickbooks_vendors — List vendorscreate_quickbooks_vendor — Create a new vendorupdate_quickbooks_vendor — Sparse-update a vendor (deactivate with active: false)list_quickbooks_invoices — List invoicescreate_quickbooks_invoice — Create a new invoiceupdate_quickbooks_invoice — Sparse-update invoice header fields (dueDate, memo, privateNote)send_quickbooks_invoice_email — Email an invoice to its customerdownload_quickbooks_invoice_pdf — Download an invoice as a PDF (saved to the system temp directory)list_quickbooks_estimates — List estimates (quotes)create_quickbooks_estimate — Create a new estimatelist_quickbooks_bills — List bills (accounts payable)create_quickbooks_bill — Create a new billlist_quickbooks_employees — List employeeslist_quickbooks_accounts — List chart of accountsText authored inside QuickBooks (customer/vendor display names, memos, line
descriptions, report cells) is attacker-influenceable, so the connector wraps
it in <untrusted-content source="quickbooks:…"> envelopes before returning
it to the model. Typed entity payloads are sanitized deny-by-default: every
string is enveloped — including strings inside arrays, which have no key
context — unless its key is a narrow structural predicate (IDs, SyncToken,
dates/timestamps, enums) and its value passes a shape guard. query_quickbooks,
get_quickbooks_entity, and reports envelope every string key and value
wholesale. Structural values such as Id, SyncToken, dates, and
amounts are left untouched so they stay usable as inputs to follow-up calls.
FSL-1.1-MIT — Functional Source License, Version 1.1, with MIT future licence. The software converts to MIT licence on 2030-04-08.
FAQs
QuickBooks Online MCP server for Model Context Protocol hosts — invoices, bills, customers, vendors, accounts
We found that @mindstone/mcp-server-quickbooks demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.