Back to skill

Security audit

智能自动记账

Security checks for vulnerabilities and agentic risk

Overview

This bookkeeping skill has a coherent purpose, but its instructions can run user-controlled text through shell commands and delete financial records without a required confirmation step.

Review before installing. The skill is not evidence of malicious intent, but it should be tightened before routine use: avoid shell-string invocation for user text, provide the missing scripts for audit, narrow ambiguous triggers, and require confirmation before deleting or exposing financial records and reports.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:55
Finding

Shell Command Injection Through Unsafely Interpolated User Input

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:55, SKILL.md:93, and SKILL.md:165
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable Code

bash
python {baseDir}/scripts/parser.py "<用户输入>"
bash
python {baseDir}/scripts/bookkeeper.py add '<json>'
bash
python {baseDir}/scripts/bookkeeper.py search "<关键词>"

Technical Analysis

The skill instructs the agent to interpolate user-controlled bookkeeping text, search keywords, and generated JSON directly into shell command strings. Shell quoting does not make this construction safe:

  • Inside double quotes, command substitutions such as $(command) and backtick substitutions can still be evaluated by the shell.
  • A single quote embedded in generated JSON can terminate the single-quoted argument used by the add command, allowing additional shell syntax to be introduced.
  • Generated JSON may contain attacker-controlled fields such as the raw input or note, so treating generated JSON as trusted does not eliminate the injection risk.

Exploitation depends on these documented commands being executed through a shell. The referenced scripts are absent from the audited package, so their own argument handling could not be reviewed; however, shell expansion occurs before Python receives the arguments.

Attack Path

  1. An attacker supplies bookkeeping text or a search keyword containing shell syntax, such as a command substitution.
  2. The agent inserts that value into one of the command templates in SKILL.md.
  3. The command is passed to a shell for execution.
  4. The shell evaluates the injected substitution or syntax before launching the intended Python program.
  5. The attacker's command executes with the operating-system permissions of the agent or skill runtime.

For the add operation, an attacker can instead place a single quote and shell metacharacters in a note or raw-input fie ...[truncated 915 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not build shell command strings from user-controlled values. Invoke Python using an argument-array API with shell processing disabled, for example the equivalent of subprocess.run(["python", script_path, user_input], shell=False, check=True).
  2. Pass structured bookkeeping records to the program through standard input or a securely created JSON file rather than embedding serialized JSON in shell source.
  3. If a shell is unavoidable, apply platform-appropriate escaping to every dynamic argument. Escaping should be treated as a fallback rather than the primary control.
  4. Validate record fields against strict schemas, including amount type and range, date format, transaction type, identifier format, maximum text length, and allowed control characters.
  5. Require deletion identifiers and year/month parameters to be parsed as bounded integers before invocation.
  6. Add the missing scripts to the package and perform a separate audit of their SQL construction, HTML output encoding, file permissions, path handling, and error handling.
  7. Add automated tests containing single quotes, double quotes, backticks, command substitutions, semicolons, newlines, and shell redirection characters to verify that all values reach Python only as literal data.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very common everyday phrases such as '买了', '收到', '看看', and '今天花', which can match normal conversation unrelated to explicit bookkeeping intent. In an agent environment, this can cause unintended activation and lead to accidental parsing, storage of sensitive financial details, or execution of later actions without the user deliberately invoking the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill defines destructive deletion behavior but does not require a warning or confirmation before removing bookkeeping entries. In this context, the stored data is personal financial history, so accidental or mis-triggered deletion can directly harm integrity and make records unreliable or unrecoverable.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The query/report triggers are described with broad examples like '查账、账单、看看、本月消费', without clear boundaries for when the skill should handle them. This ambiguity can cause the agent to invoke the skill during general financial discussion and expose stored bookkeeping data unintentionally.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Report-generation triggers such as '报告、月报、可视化、生成报告' are generic and can overlap with unrelated requests for reports in other contexts. Misrouting such requests to this skill could generate financial reports unexpectedly and expose local spending data or create unintended files.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Deletion examples include generic phrases like '撤销' and '删掉第5条', which may be interpreted in contexts outside bookkeeping or without sufficient certainty about the target record. Because deletion is destructive, ambiguous activation can lead to irreversible loss of financial records.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.