Back to skill

Security audit

Splitwise CLI

Security checks for vulnerabilities and agentic risk

Overview

This Splitwise skill is coherent and not malicious, but it gives an agent access to sensitive shared-expense data and destructive financial record changes without enough explicit user-control guidance.

Review before installing. This skill relies on your local Splitwise OAuth session and can expose balances, friends, groups, and expense history to the agent. Only use it if you are comfortable with the agent operating your Splitwise CLI, and require explicit confirmation before creating expenses, recording settlements, or deleting records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger description is unusually broad and explicitly says even casual mentions should activate the skill, which can cause the agent to invoke a financial-management capability when the user did not clearly intend it. In this context, unintended activation is dangerous because the skill can read balances and create, settle, or delete shared-expense records, leading to privacy exposure or unintended account changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation includes state-changing and destructive operations such as settlements and expense deletion, but it does not instruct the agent to require explicit confirmation before executing them. In a financial recordkeeping skill, omission of confirmation guidance increases the risk of accidental loss of data integrity, mistaken settlements, or deletion of valid expense records.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.