T09 · Insecure Skill Coding Practices
- Location
scripts/add_transaction.py:25- Finding
Sensitive financial data files are created without explicit restrictive permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed local personal-finance tracker, with privacy and data-quality caveats but no evidence of hidden, remote, destructive, or credential-seeking behavior.
Install only if you are comfortable keeping manually entered income, expense, budget, and note data as local plaintext files. Use it in a private user account, avoid putting secrets or account numbers in notes, and consider tightening file permissions or deleting ~/.openclaw/workspace/first-million/ when you no longer want the data retained.
scripts/add_transaction.py:25Sensitive financial data files are created without explicit restrictive permissions
scripts/budget.py:80Invalid numeric values can corrupt financial records and crash budget reports
The trigger examples for financial advice are broad, everyday phrases like 'How to save more' and 'Financial tips', which can cause the skill to activate in situations where the user did not clearly intend to use this project-local finance tool. Over-broad invocation increases the chance of the agent reading or writing local financial data unnecessarily and giving personalized finance guidance without sufficiently explicit user intent.
The skill explicitly persists sensitive financial data in a fixed workspace path under ~/.openclaw/workspace/first-million/, creating session-to-session retention of income, expenses, budgets, and notes. Even without network access, persistent storage of personal financial records can expose sensitive data to other skills, users on the same environment, or later unintended accesses if isolation and consent are weak.
## Scope & safety
- **Data:** Ledger and budget data are stored in OpenClaw workspace: `~/.openclaw/workspace/first-million/` (`ledger.json`, `budget.json`). Scripts read and write only these files; no network or credentials.
- **Scripts:** Only the three project scripts under `scripts/` are used; no shell pipelines, no remote fetches, no credentials.
- **References:** Only project Markdown files under `references/` are read. No external URLs or APIs.
The script emits user-facing report text entirely in Chinese, including headings and labels, while the rest of the tool usage and CLI help are in English. This creates a language/locale policy concern because the skill forces a specific output language without user opt-in or justification.
This code emits report titles and status labels in Chinese (for example, '预算检查报告', '剩余', '超支', and '分类预算') with no option to choose another language. That creates a natural-language locale policy issue because the skill imposes a specific language on all users without documented opt-in or justification.
This markdown file consists solely of Chinese-language instructional content and does not indicate that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.
The entire skill content is presented only in Chinese, with no indication that users may choose another language or locale. Under the policy rule for natural-language violations, a skill that effectively forces a specific language without opt-in can be flagged unless the locale constraint is documented and justified.
No suspicious patterns detected.