Back to skill

Security audit

Journey to First Million

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local personal-finance tracker, with privacy and data-quality caveats but no evidence of hidden, remote, destructive, or credential-seeking behavior.

Install only if you are comfortable keeping manually entered income, expense, budget, and note data as local plaintext files. Use it in a private user account, avoid putting secrets or account numbers in notes, and consider tightening file permissions or deleting ~/.openclaw/workspace/first-million/ when you no longer want the data retained.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/add_transaction.py:25
Finding

Sensitive financial data files are created without explicit restrictive permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/budget.py:80
Finding

Invalid numeric values can corrupt financial records and crash budget reports

Content
View full analysis
= 0 else "⚠️" report.append(f"{status} 总预算: ¥{total_spent:.2f} / ¥{budget['total']:.2f} ({pct:.1f}%)") ``` `scripts/budget.py:80-85` ```python for cat, limit in budget["categories"].items(): spent = spending.get(cat, 0) remaining = limit - spent pct = (spent / limit) * 100 status = "✅" if remaining >= 0 else "⚠️" report.append(f" {status} {cat}: ¥{spent:.2f} / ¥{limit:.2f} ({pct:.1f}%)") ``` ### Technical Analysis Transaction amounts and budget limits are converted with `float()` but ar ...[truncated 2416 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger examples for financial advice are broad, everyday phrases like 'How to save more' and 'Financial tips', which can cause the skill to activate in situations where the user did not clearly intend to use this project-local finance tool. Over-broad invocation increases the chance of the agent reading or writing local financial data unnecessarily and giving personalized finance guidance without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill explicitly persists sensitive financial data in a fixed workspace path under ~/.openclaw/workspace/first-million/, creating session-to-session retention of income, expenses, budgets, and notes. Even without network access, persistent storage of personal financial records can expose sensitive data to other skills, users on the same environment, or later unintended accesses if isolation and consent are weak.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
## Scope & safety

- **Data:** Ledger and budget data are stored in OpenClaw workspace: `~/.openclaw/workspace/first-million/` (`ledger.json`, `budget.json`). Scripts read and write only these files; no network or credentials.
- **Scripts:** Only the three project scripts under `scripts/` are used; no shell pipelines, no remote fetches, no credentials.
- **References:** Only project Markdown files under `references/` are read. No external URLs or APIs.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script emits user-facing report text entirely in Chinese, including headings and labels, while the rest of the tool usage and CLI help are in English. This creates a language/locale policy concern because the skill forces a specific output language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits report titles and status labels in Chinese (for example, '预算检查报告', '剩余', '超支', and '分类预算') with no option to choose another language. That creates a natural-language locale policy issue because the skill imposes a specific language on all users without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file consists solely of Chinese-language instructional content and does not indicate that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire skill content is presented only in Chinese, with no indication that users may choose another language or locale. Under the policy rule for natural-language violations, a skill that effectively forces a specific language without opt-in can be flagged unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.