Back to skill

Security audit

Refund Radar

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent local financial-audit helper, but it embeds an undisclosed external link in every generated financial report despite claiming no network-related behavior.

Install only if you are comfortable storing financial transaction reports and raw analysis files locally under ~/.refund_radar. Before sharing or opening generated HTML reports, review or remove the footer link, and verify the refund_radar Python module you will run because this artifact does not include the implementation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
assets/template.html:719
Finding

Persistent External Promotion Embedded in Generated Financial Reports

Content
View full analysis

Vulnerability Details

File Location: assets/template.html:719-721
Vulnerability Type: Stable output modification through mandatory external attribution
Risk Level: High

html
<footer>
    Generated by <a href="https://clawdhub.com">refund-radar</a> • {{GENERATED_AT}}
</footer>

Technical Analysis

The report template contains a fixed hyperlink to an external domain. SKILL.md:91-104 instructs the Agent to use the structure of assets/template.html when generating reports, so the external promotion is included as part of the normal output rather than being an optional, user-approved attribution.

This behavior modifies every generated financial report with attacker-controlled branding and a clickable external destination unrelated to the local transaction-analysis function. It also conflicts with the local-only privacy assurances in SKILL.md:168-172, which state that there are no network calls and that user data stays on the local machine. Although merely opening the report does not initiate a demonstrated network request, clicking the footer link causes the browser to connect to the external domain.

No evidence was found that the link automatically transmits bank-statement contents, executes remote code, or grants system privileges. Exploitation requires user interaction.

Attack Path

  1. A user invokes the Skill and provides sensitive bank or card transaction data.
  2. The Agent follows SKILL.md:91-104 and generates an HTML report using assets/template.html.
  3. The generated report automatically includes the fixed external link in its footer.
  4. The user or another report recipient opens the generated report and clicks the attribution link.
  5. The browser navigates to the third-party domain and discloses ordinary connection metadata, such as the client IP address, browser characteristics, and request headers, according to browser behavior and policy.
  6. The external destination may th ...[truncated 657 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the external hyperlink from the default report template.
  2. If attribution is required, use non-clickable plain text that does not cause external navigation.
  3. Make all external links opt-in and obtain explicit user approval before including them in generated reports.
  4. Clearly distinguish optional attribution from report content and provide a configuration option that disables it by default.
  5. Add rel="noopener noreferrer" to any approved external link opened in a new browsing context.
  6. Consider applying a restrictive Content Security Policy to generated reports, such as limiting connections and resources to local content, while recognizing that navigation controls may require additional browser-specific policy.
  7. Update the privacy documentation so that it accurately explains any user-initiated external navigation that remains.
  8. Add a release test that scans generated reports for unapproved external URLs.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "analyze my credit card transactions" is broad enough to match common user requests involving sensitive financial data without clearly signaling the skill boundary or the fact that local files and persistent outputs may be involved. In a skill that processes bank statements and writes reports to disk, overly broad invocation language increases the chance of accidental activation and unnecessary exposure of highly sensitive financial information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrase "find recurring charges in my statement" is vague and does not make clear that the skill will parse sensitive financial records, generate stored reports, and maintain learned state. Because this skill operates on bank and card statements, ambiguity raises the risk of users invoking it without understanding the privacy implications or the persistence of outputs on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly handles highly sensitive bank and card transaction data and states that reports and state are written to ~/.refund_radar/, but it does not prominently warn users before collection and processing that this data will persist locally. In the financial context, undisclosed local persistence can expose transaction history, merchant names, spending patterns, and dispute-related notes to other local users, backups, shared devices, or malware.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="en", which hard-codes English as the page language. Under the policy criteria, forcing a specific language without user opt-in or documented justification is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.