Back to skill

Security audit

candor-finance

Security checks for vulnerabilities and agentic risk

Overview

This finance skill is coherent and not malicious, but it asks for broad authenticated access to sensitive financial records and permits some persistent budget and goal changes without exact final confirmation.

Install only if you are comfortable giving an authenticated Candor CLI agent broad access to your financial workspace and allowing it to maintain persistent financial memory. For exploratory planning, tell the agent explicitly not to save budgets, goals, notes, rules, or schedules unless you confirm the exact change.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · methods/candor-money-recovery/references/workflows.md (reported line 88)May include surrounding context.

md
inflow `USD 860.00` to checking `acc_3d1f8b2c`. No matching deposit in
   transactions through Aug 10 (query action `act_9c2e417a`; coverage at
   that query: checking transactions complete since 2026-06-01, fresh
   through Aug 10, no caveats). Payroll deposits post as ACME PAYROLL;
   reimbursements have posted separately as ACME EXP.

   **Recipe:** `candor transactions list --since 2026-08-10 --until

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is intentionally very broad, triggering on nearly any task involving money, financial records, prior decisions, or saved plans. In an agent-routing context, this can cause over-selection of a high-authority finance skill, unnecessarily exposing sensitive financial context and increasing the chance the agent performs or proposes actions beyond the user's immediate intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The method explicitly says to save a budget drafted from the user's records 'without waiting for a yes to each line' and to 'maintain the budget from then on,' which conflicts with earlier guidance not to save unsettled scenarios. In a finance skill, this can cause unauthorized writeback of budget decisions, silently converting exploratory discussion into persistent financial records that may influence later advice and actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to save budget drafts without explicit per-action confirmation and without a mandatory warning about writeback effects. Because this skill operates on sensitive financial plans, an agent could persist inferred allocations the user did not intend to adopt, creating integrity issues in the user's budget history and affecting future financial guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow explicitly says to save a budget state change without requiring explicit user confirmation to the exact draft, which enables the agent to persist financial planning changes based on inferred intent rather than an unambiguous approval. In a personal-finance skill, writes to budgets can materially alter the user's saved plans, follow-on decisions, and trust in the system, especially if the agent misinterprets preferences or is prompt-injected into making changes the user did not clearly authorize.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The method explicitly authorizes persisting goal changes 'without asking for a yes to an exact draft,' which weakens user consent around writes to financial planning records. In a personal-finance skill, silently saving targets, dates, or priorities can create inaccurate commitments, influence later advice, and cause downstream decisions to rely on unapproved data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

This instruction enables autonomous decision-making over sensitive financial records by allowing the agent to save a goal once the conversation 'settles it' rather than obtaining explicit approval. Because the skill operates on budgets, balances, transactions, and goals, even well-intentioned inference can misrepresent the user's preferences and materially alter the persistent financial context used in future recommendations.

Content

Scanner excerpt · methods/candor-goals-scenario-planning/METHOD.md (reported line 60)May include surrounding context.

md
## Domain decisions

You can recommend a target, date or priority. Save the goal as the conversation
settles it, without asking for a yes to an exact draft: use the user's words and
only figures and dates they gave or the records show, tell them briefly what
you saved, and edit it when it changes. Factual progress and linkage repairs do
not retarget a goal on their own.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow explicitly instructs the agent to persist a financial goal once the conversation 'settles it' and to 'not ask for a yes to an exact draft,' which weakens explicit user consent before writing sensitive financial planning data. In a personal-finance skill, silently or implicitly saving goals can create incorrect records, unauthorized planning artifacts, and downstream decisions based on assumptions the user did not clearly approve.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow materially expands the skill from general personal-finance organization into tax-preparation support, including tax-record organization and export handoff. In a finance skill handling sensitive financial history, this scope creep can cause the agent to perform regulated or higher-risk activities the manifest does not clearly authorize, increasing the chance of incorrect tax-related categorization, misleading user reliance, and over-collection or repurposing of sensitive data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · methods/candor-workplace-retirement/METHOD.md (reported line 46)May include surrounding context.

md
captured at the current rate. Show the arithmetic and its inputs.
- Treat statutory contribution limits as external facts: use a current
  authoritative source, name the tax year, and separate employee deferral,
  employer, and combined limits. Never reuse a remembered figure without
  checking its year.
- When the user changes a deferral, the change shows up on a later paystub or
  contribution record. Write a timed re-check note with the baseline and

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/monitoring.md (reported line 6)May include surrounding context.

md
Use the host's durable scheduler for a requested later check or recurring task.
Recover the user's purpose, cadence, time zone, notification preference and stop
condition. Ask only for missing choices. An explicit scheduling request is
already authorization; do not ask the user to opt in again. Setup and workspace
access alone do not authorize a schedule.

## Preserve the requested task

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · methods/candor-evidence-capture/METHOD.md (reported line 161)May include surrounding context.

md
Receiving a file alone does not authorize import. A request to add, import or
test supplied evidence covers validation, preview, inspected apply, verification
and a requested or necessary revert. Resolve ambiguous account identity or
conflicts with trusted state before applying; do not silently expand scope.

## Stopping conditions

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow instructs creation of a persistent note containing insurance-renewal details, deadlines, missing facts, and responsible parties, but it does not explicitly require informing the user that this information will be stored. In a finance/insurance context, those notes can contain sensitive personal and financial data, so silent persistence creates a privacy and consent risk even if the action is operationally useful.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.