Back to skill

Security audit

Expense Report

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a straightforward expense-report formatter, with minor cautions about broad triggers and generated-report attribution.

Before installing, be aware that the skill may activate on broad expense-related requests and may add generator attribution to formal reports. Review reports before sharing them, especially when they contain private financial details or need to meet employer/client formatting rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:118
Finding

Mandatory Branded Attribution in Generated Reports

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 118-126
Vulnerability Type: Mandatory user-facing output manipulation
Risk Level: Low

Evidence

markdown
### Relatório Completo (para prestação de contas formal)

Inclui:
- Cabeçalho com nome do responsável e período
- Tabela detalhada (data, descrição, categoria, valor, reembolsável)
- Resumo por categoria
- Total geral
- Legenda (✅ reembolsável | ❌ pessoal)
- Assinatura eletrônica: "Gerado por Expense Report Generator em [data]"

Technical Analysis

The skill directs the agent to insert a fixed product attribution into every complete expense report. Because this instruction is embedded in the skill workflow rather than presented as an optional output preference, loading and following the skill alters the report by adding third-party branding that the user may not have requested.

The phrase is also described as an “electronic signature.” This may cause recipients to mistake automated product attribution for a meaningful approval, attestation, or signature. The behavior does not execute code, access additional resources, or bypass system permissions, but it affects the integrity and suitability of generated business documents.

Attack Path

  1. A user invokes the skill and requests a complete expense report.
  2. The agent follows the complete-report requirements in SKILL.md.
  3. The agent appends the fixed Expense Report Generator attribution.
  4. The resulting formal report contains unsolicited branding represented as an electronic signature.
  5. If submitted without review, the branded statement may be interpreted as an attestation or may violate the recipient’s document-formatting requirements.

Impact Assessment

No operating-system privileges, credentials, persistent access, or code-execution capabilities can be obtained through this issue. Its scope is limited to user-facing reports generated under the complete-repor ...[truncated 241 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the mandatory attribution from the default complete-report format.
  • Do not label automated generator attribution as an electronic signature.
  • Offer attribution only as an explicit, opt-in formatting option.
  • Obtain user confirmation before adding branding or generator metadata to formal documents.
  • If provenance is required, use neutral metadata such as “Generated on [date]” without a product name.
  • Clearly distinguish document-generation metadata from approval, authorization, and legally meaningful signatures.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common finance-related requests such as 'organizar meus gastos' or 'quanto gastei esse mês/semana', which could cause the skill to activate when the user did not explicitly ask for an expense-report workflow. In a user-invocable skill that can read and write, unintended invocation can lead to incorrect handling of sensitive financial text, unwanted file generation, or confusion about which agent behavior is acting on the user's data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.