Back to skill

Security audit

Tmp.Rd8dBLUSJc

Security checks for vulnerabilities and agentic risk

Overview

This Credit Karma skill is coherent, but it should be reviewed carefully because it asks users to expose and store sensitive session cookies while running external code that can access financial data.

Install only if you are comfortable giving the MCP server and related extension access to your Credit Karma session and synced financial data. Prefer a pinned, audited package version, avoid storing full Cookie headers in project files, keep any .env or MCP config out of source control and backups, and remove stored cookies and the local SQLite database when no longer needed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Execution of Unpinned Third-Party Packages and Source Code

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:61
Finding

Sensitive HttpOnly Cookies Exposed Through an External Browser Extension

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:43
Finding

Plaintext Storage of Full Credit Karma Session Cookies

Content
View full analysis
`. ``` ```markdown **2. ck_set_session MCP tool:** From within Claude, call `ck_set_session` with a Cookie header you copied from DevTools (see below). The tool persists it to `.env`. ``` ### Technical Analysis The documentation instructs users to store a complete authenticated Cookie header in MCP configuration or in a project-level `.env` file. It also states that `ck_set_session` persists the supplied header to `.env`. These are plaintext storage mechanisms. Such files may be readable by other local processes or users, included in backups, indexed by development tools, exposed in support bundles, or accidentally committed to source control. Project-scoped `.env` files are particularly susceptible to accidental disclosure. Requesting the complete Cookie header also potentially collects more cookie values than the two cookies identified elsewhere as necessary. This violates data minimization and increases the consequences of disclosure. No file-permission enforcement, encryption, secret-manager integration, redaction requirement, or credential deletion process is documented. ### Attack Path 1. A user copies the full Cookie request header from an authenticated Credit Karma browser session. 2. The user places it in `.mcp.json`, `~/.claude/mcp.json`, or passes it to `ck_set_session`. 3. The MCP or user workflow writes the value to a plaintext `.env` file. 4. The file is accidentally committed, synchronized, backed up, indexed, logged, or read by ano ...[truncated 801 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

MCP Config Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

Option A — npx (recommended)

Add to .mcp.json in your project or ~/.claude/mcp.json:

json
{

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to copy authentication cookies from DevTools or let an extension read HttpOnly cookies, but it does not prominently warn that these credentials may grant account access and that transaction data is persisted locally. For a financial-data skill, missing disclosure materially increases the risk of users exposing session secrets or storing regulated/sensitive data without informed consent.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
97% confidence
Finding

The skill explicitly describes reading HttpOnly Credit Karma cookies via chrome.cookies.get and operating direct-to-API from Node, which matches credential-harvesting behavior even if framed as convenience. In the context of a personal-finance integration, browser-session cookie extraction can enable full account access and is especially dangerous because it targets highly sensitive financial data and bypasses safer delegated auth models like OAuth.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

RKID=...; CKAT=eyJ...%3BeyJ...; ..." } } } }

text

Or use a `.env` file in the project directory with `CK_COOKIES=<value>`.

### Getting CK_COOKIES (optional)

Three onboarding paths, in priority order:

**1. fetchproxy extension (easiest — no env vars):** Install the [fetchproxy 0.3.0 extension](https://github.com/chrischall/fetchproxy), sign into creditkarma.com once, and leave `CK_COOKIES` **unset**. The MCP reads HttpOnly `CKAT` + `CKTRKID` cookies on the first tool call via `chrome.cookies.get`, then operates direct-to-API from Node.

**2. ck_set_session MCP tool:** From within Claude, call `ck_set_session` with a Cookie header you copied from DevTools (see below). The tool persists it to `.env`.

**3. Manual (DevTools):**
1. Log in to [creditkarma.com](https://www.creditkarma.com) in Chrome
2. DevTools → **Network** → any creditkarma.com request → **Request Headers**
3. Right-click the `cookie` header → **Copy value**
4. Paste into `CK_COOKIES` in your Claude

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
The MCP handles auth automatically once any of the three paths is configured.

- Access token: ~15 min TTL, auto-refreshed transparently
- Refresh token: ~8 hours TTL
- When expired:
  - **fetchproxy path:** sign back into creditkarma.com — the MCP reads fresh cookies on the next tool call

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description is broad enough to match generic personal-finance requests, which can cause the skill to activate when the user did not specifically intend to use Credit Karma. In this skill, unintended invocation is more concerning because the skill handles highly sensitive financial records and may prompt use of stored authentication state or local synced data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.