Back to skill

Security audit

Technical Accounting Research

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate accounting-research purpose, but it requires running an unpinned external GitHub repository and installing local Python dependencies as part of normal use.

Review this before installing. It should only be used if you are comfortable with the agent cloning and running the FinResearchClaw repository, installing Python dependencies, using web research, and writing files such as DOCX memos locally. Prefer a pinned, reviewed commit or signed release, run it in a restricted environment, and confirm output paths before using it with confidential accounting or client information.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
README.md:39
Finding

Mandatory Retrieval and Execution of an Unpinned Remote Repository

Content
View full analysis

Vulnerability Details

File Location: README.md:39-47; SKILL.md:16-23; SKILL.md:76-82; SKILL.md:146; SKILL.md:155-171
Vulnerability Type: Remote payload retrieval and supply-chain execution
Risk Level: Medium

Vulnerable Code and Instructions

README.md:39-47:

bash
Install FinResearchClaw locally first:

```bash
git clone https://github.com/ChipmunkRPA/FinResearchClaw.git ~/.openclaw/workspace/AutoResearchClaw
cd ~/.openclaw/workspace/AutoResearchClaw
python3 -m venv .venv
source .venv/bin/activate
pip install -e .
text

`SKILL.md:16-23`:

```text
Before using this skill for substantive completion, install and make available the local FinResearchClaw repo:

1. Clone or install `https://github.com/ChipmunkRPA/FinResearchClaw`
2. Ensure the local repo is available at `~/.openclaw/workspace/AutoResearchClaw` unless a different local path is intentionally configured
3. Ensure Python is available and create a task-local virtual environment when needed
4. Install memo-generation dependencies such as `python-docx` when DOCX output is required

If FinResearchClaw is not installed locally and runnable, do not treat the full research workflow as ready. Fix that prerequisite first.

SKILL.md:76-82:

text
- Invoke FinResearchClaw for every task handled by this skill, regardless of output format.
- Execution for memo, email, and q-and-a outputs should all wrap the FinResearchClaw repo/workflow even if the accounting issue is straightforward.
- The FinResearchClaw-backed run must occur before any user-facing technical conclusion is given. Do not short-circuit from clarified facts directly to an accounting answer.
- The skill may create a task-local virtual environment for the run if needed.
- Do not skip or bypass the FinResearchClaw path. If the repo is unavailable, dependencies are missing, or the workflow fails to run, stop and troubleshoot the FinResearchClaw envir
...[truncated 4051 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin FinResearchClaw to a specific, reviewed commit hash or cryptographically signed immutable release rather than cloning the mutable default branch.
  2. Publish and verify a cryptographic checksum or signature before installation or execution.
  3. Replace editable installation with a reproducible installation from a reviewed artifact.
  4. Lock all transitive Python dependencies to exact versions and hashes, and install them with hash verification enabled.
  5. Review the pinned repository and its build configuration before approving it as an execution dependency.
  6. Run external research tooling in a sandbox or container with a restricted filesystem, minimal environment variables, no unnecessary credentials, and network access limited to required destinations.
  7. Avoid making remote code execution mandatory. Require explicit user consent before fetching or executing external code, and provide a safe local-only fallback.
  8. Store the approved dependency in a versioned, read-only location and verify its integrity before each run.
  9. Document a controlled update process requiring security review whenever the pinned revision or dependency lock file changes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to read local files, inspect local repo paths, and invoke local scripts, but it does not declare an explicit tool scope such as allowed-tools or permissions. That creates a least-privilege gap where the agent may access filesystem capabilities implicitly, reducing transparency and increasing the chance of unintended local data exposure or broader tool use than the user expects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The skill explicitly permits creating and using a task-local virtual environment to run supporting code, which introduces persistent filesystem artifacts and potentially executable dependencies into the user's environment. This increases risk of contamination across sessions, unintended reuse of installed packages, and supply-chain compromise if dependencies or repos are unsafe.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
Handle transaction-specific accounting questions through a fixed sequence: gather facts, confirm output format, ensure the local FinResearchClaw repo is installed and runnable, route the task through that wrapped repo/workflow, research guidance online, apply standards, and deliver the requested output.

For all tasks under this skill — memo, email, and q-and-a alike — the workflow must wrap and leverage the local FinResearchClaw repo/workflow as a required research-and-drafting execution layer. This is mandatory, not optional, and applies even when the accounting issue appears straightforward. The skill may create and use a task-local virtual environment when needed to run the repo or supporting document-generation dependencies. FinResearchClaw is a required support engine for research depth and drafting quality across all output modes; authoritative accounting conclusions must still be grounded in ASC / SEC / AICPA / clearly labeled interpretive guidance.

## Prerequisites

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill defaults to creating a DOCX file in ~/Downloads without first requiring explicit user consent for local file creation. Automatic writes to a user directory can create privacy, overwrite, and persistence risks, especially when the content may contain sensitive accounting facts or client-ready material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill mandates web research and use of an external/local repo workflow but does not clearly warn the user that the task may involve network access and interaction with external resources. This can expose user-provided facts to third-party services indirectly, create supply-chain risk through dependency use, and violate user expectations about offline or local-only processing.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
- Example report payload: [references/example_report_input.json](references/example_report_input.json)
- DOCX generator: `scripts/build_accounting_report_docx.py`
- FinResearchClaw repo: `https://github.com/ChipmunkRPA/FinResearchClaw`
- FinResearchClaw local skill reference: `~/.openclaw/skills/finresearchclaw/SKILL.md`

## Dependency

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

The runtime section explicitly directs initialization of a local Python virtual environment and dependency installation when the repo is not ready, creating durable local state as part of normal execution. This is risky because it normalizes environment mutation and persistence as a default recovery action, broadening the attack surface and leaving artifacts that may affect future sessions.

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
## Runtime / Environment Expectations

- Memo-mode runs are allowed to create and use a task-local Python virtual environment.
- FinResearchClaw default repo path: `~/.openclaw/workspace/AutoResearchClaw`
- If the repo or its dependencies are not ready, initialize a local venv for the task and install only the dependencies needed for the memo workflow.
- If FinResearchClaw cannot be executed after reasonable setup attempts, disclose that explicitly and fall back to a non-FinResearchClaw path only as an exception, not the default.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill repeatedly states that no task may complete without a successful FinResearchClaw run, but later allows fallback to a non-FinResearchClaw path if execution fails. Contradictory control logic is dangerous because it encourages bypass of a supposedly mandatory verification path under failure conditions, which can lead to inconsistent behavior, weakened safeguards, and user-unexpected execution paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill authorizes creation of task-local virtual environments and package installation without explicit advance notice that the local Python environment will be modified. Even when changes are task-local, they introduce persistence, package-supply-chain exposure, disk writes, and possible conflicts that the user may not expect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.