Back to skill

Security audit

Clawed Invoice Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward local invoice PDF generator, with the main caution that generated invoices can contain sensitive billing and bank details and are written to disk.

Before installing, be comfortable with a local Node script that reads invoice JSON/config files and writes a PDF containing customer and payment details. For real invoices, avoid shared temp locations, set outputDir to a private secured directory, protect any config containing IBAN/SWIFT details, and delete generated PDFs when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly writes invoice PDFs to disk and invoices commonly contain sensitive personal and financial data, including customer addresses, account references, and bank details. Omitting a warning about this storage behavior can lead users to place regulated or confidential billing data into insecure locations such as shared /tmp directories or persistent volumes without appropriate handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script accepts input.outputDir and writes the generated PDF to that path without restriction. If untrusted input can reach this field, the skill can be abused as a file-write primitive to place sensitive invoices or overwrite files in arbitrary writable locations on the host filesystem, which exceeds the intended narrow invoice-generation scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persists full invoice PDFs containing customer names, addresses, invoice numbers, and payment details to local disk by default, but gives no warning or control around retention. In constrained or shared environments, this can lead to unintended storage of sensitive billing data where other users, processes, backups, or logs may later access it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a plain Node.js PDF invoice generator with custom branding and payment details, but does not indicate any need to inspect process environment or load configuration from arbitrary external paths. Reading process.env.INVOICE_CONFIG and supporting an override path via configuration introduces ambient host-state dependency beyond the core document-rendering role.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.