cfo-skill — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cfo-skill (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
## ⚠️ DISCLAIMER
>
This skill displays data. It is NOT financial, legal, tax, accounting, or investment advice.
>
Numbers may be stale, miscategorized, or reflect bugs in upstream systems. Frameworks below (LTV:CAC, runway, burn multiple, Rule of 40) are heuristics, not guarantees. Decisions about hiring, fundraising, distributions, taxes, or solvency must be made by you in consultation with a qualified CFO, accountant, lawyer, or tax advisor. The author and contributors accept no liability for decisions made based on this skill's output.
Drop four CSVs into a folder, run one command, get an Excel workbook. Works with any CRM/bank/billing stack, Attio, HubSpot, Salesforce, Pipedrive, Mercury, Brex, Stripe, Chargebee, Ramp, Pleo, whatever.
Templates live in templates/. Realistic example data lives in examples/ so you can try the pipeline before plugging in real data.
python skills/cfo-skill/run.py --source csv --csv-dir ./my-data --output cfo.xlsxCSV schemas (column headers in templates/):
| File | Columns |
|---|---|
customers.csv | customer_id, customer_name, status, signed_up_at, churned_at, mrr, plan |
cash_movements.csv | date, account, direction, amount, currency, counterparty, category, department, note |
invoices.csv | invoice_id, customer, issued_at, due_at, amount, currency, status |
balances.csv | account, currency, balance, as_of |
status values: active, churned, lead (only active counts toward MRR). direction values: in, out. Invoice status values: paid, unpaid, draft.
Set credentials in your environment, run the puller, get the same Excel workbook from live data.
python skills/cfo-skill/run.py --source api --providers all --output cfo.xlsxOr pick specific providers, they run in the order you list, and later writers win on customers.csv / invoices.csv:
python skills/cfo-skill/run.py --source api --providers qonto,stripe,moss # Stripe-billed SaaS
python skills/cfo-skill/run.py --source api --providers qonto,attio,moss # CRM-driven (no Stripe)
python skills/cfo-skill/run.py --source api --providers qonto,attio,stripe,moss # both, Stripe wins on MRRProvider-by-provider:
| Provider | Writes | Best at | Reference |
|---|---|---|---|
| Stripe | customers.csv (with real MRR), invoices.csv | Authoritative SaaS revenue. Use this if you bill via Stripe. | references/stripe.md |
| Attio | customers.csv | CRM-driven customer state, plan, lifecycle | references/attio.md |
| Qonto | balances.csv, cash_movements.csv, invoices.csv | Bank truth, cash position, transactions, AR | references/qonto.md |
| Moss | appends to cash_movements.csv | Categorized card spend, vendors, departments | references/moss.md |
Each puller writes its slice to a temp folder; the same compute layer then generates the Excel workbook. You don't have to use all four. A Stripe + Mercury founder can run --providers stripe and use CSV templates for the bank side. A HubSpot + Brex founder skips API mode entirely and uses CSV for everything.
Only set the ones for providers you actually use.
| Provider | Variables |
|---|---|
| Stripe | STRIPE_SECRET_KEY (use a restricted key with read on customers, subscriptions, invoices, payouts) |
| Attio | ATTIO_API_KEY. Optional: ATTIO_MRR_ATTR, ATTIO_STATUS_ATTR, ATTIO_ACTIVE_VAL, ATTIO_CHURNED_ATTR, ATTIO_PLAN_ATTR, ATTIO_NAME_ATTR |
| Qonto | QONTO_API_KEY + QONTO_SECRET_KEY (the "secret key" is your Qonto org slug) |
| Moss | MOSS_KEY_ID + MOSS_SECRET_KEY (OAuth client credentials, scope read) |
Skill is read-only, never request write scopes. Never log or echo a secret.
Eight sheets:
| Metric | Formula | Heuristic flags |
|---|---|---|
| Cash balance | sum of bank account balances | - |
| Runway | cash ÷ trailing 3-month avg net burn | <12 mo red, 12-24 mo yellow |
| Burn multiple | net burn ÷ MRR | >2× red |
| MRR / ARR | sum of active customer MRR × 12 | - |
| Customer concentration | top-N MRR ÷ total MRR | >25% top-1 red |
| AR aging | unpaid invoices bucketed by days past due | 60+ days red |
| DSO | (AR ÷ 90d issued sales) × 90 days | <30 green, >60 red |
| Spend by category | sum of outflows grouped by category | - |
| Top vendors | sum of outflows grouped by counterparty | - |
| Recurring vendors | counterparty appearing 3+ times in trailing window | - |
| Departmental burn | sum of outflows grouped by department | - |
Frameworks used (LTV:CAC, Rule of 40, Magic Number, etc.) live in references/metrics-benchmarks.md. Bootstrapped case studies in references/case-studies.md.
For any of these: "I can show you the numbers. The decision is for you and a qualified advisor."
run.py with appropriate flags, or read the CSVs directly via cfo.load_all() + cfo.summarize().Frameworks, benchmarks, and case studies adapted from EveryInc/charlie-cfo-skill (MIT, © 2026 Every).
Data layer (Stripe + Attio + Qonto + Moss pullers + CSV templates + Excel writer) by 5050Growth.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.