Back to skill

Security audit

Monarch Money

Security checks for vulnerabilities and agentic risk

Overview

This Monarch Money skill is broadly coherent but needs review because it handles financial credentials and account-changing actions with under-disclosed and unsafe secret-handling behavior.

Review before installing. Use this only in a trusted environment, avoid passing the password or MFA seed on the command line, do not enable debug logging during login, treat ~/.mm/session.json as a live credential, and restrict any agent from calling create/delete or deleteAllTransactionRules operations without explicit confirmation. Update dependencies and fix credential redaction/session storage before production use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
lib/client/auth/AuthenticationService.ts:393
Finding

Authentication Credentials and TOTP Codes Exposed Through Debug Logging

Content
View full analysis
= { username: email, password, trusted_device: true, supports_mfa: true, supports_email_otp: true, supports_recaptcha: true } if (mfaSecretKey) { const code = totp.authenticator.generate(mfaSecretKey) loginData.totp = code } ``` ### Technical Analysis The default console logger writes debug output to standard error when `MONARCH_LOG_LEVEL=debug`. Because the complete authentication request body is passed to the logger without redaction, debug output includes the plaintext account password and current MFA code. Standard error is frequently captured by CI systems, container runtimes, process supervisors, terminal recording software, or centralized logging platforms. This can expand access to authentication secrets beyond the process that legitimately needs them. Although the TOTP code is short-lived, the password remains reusable. A captured password and timely TOTP code can be used for immediate authentication. The disclosure also u ...[truncated 1242 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/client/auth/SessionStorage.ts:62
Finding

Bearer Session Token Stored in Plaintext by Default

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/client/auth/SessionStorage.ts:148
Finding

Public Status and Version APIs Return the Full Session Token

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
cli/commands/auth.ts:16
Finding

CLI Accepts Passwords and MFA Seeds Through Command-Line Arguments

Content
View full analysis
', 'Email address') .option('-p, --password ', 'Password') .option('--mfa-secret ', 'MFA secret (optional)') ``` The project documentation also demonstrates explicit credentials on the command line: ```bash monarch-money auth login -e email@example.com -p password --mfa-secret SECRET ``` ### Technical Analysis Command-line arguments are not an appropriate channel for passwords or long-lived MFA seeds. Depending on the operating system and shell configuration, arguments can be exposed through: - Shell history files. - Process inspection tools. - Operating-system audit records. - Terminal session recording. - CI command logs. - Wrapper scripts and job metadata. The MFA seed is more sensitive than a single TOTP code because anyone who obtains the seed can generate future valid codes. Combining a captured password and MFA seed can therefore defeat both authentication factors for an extended period. Environment variables, which are also supported by the project, can reduce shell-history exposure but are still readable in some process and diagnostic contexts. A protected interactive prompt or credential manager is preferable. ### Attack Path 1. A user follows the documented command and supplies `--password` and `--mfa-secret`. 2. The shell records the complete command in history, or the operating system exposes the process arguments while the command is running. 3. A local attacker, support operator, CI user, or log reader obtains the recorded arguments. 4. The attacker recovers the account password and long-lived TOTP seed. 5. The attacker generates a valid MFA code and authenticates as the victim. 6. The attacker retains ...[truncated 553 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (88)

Known Vulnerable Dependency: handlebars==4.7.8 — 8 advisory(ies): CVE-2026-33916 (Handlebars.js has Prototype Pollution Leading to XSS through Partial Template In); CVE-2026-33937 (Handlebars.js has JavaScript Injection via AST Type Confusion); CVE-2026-33938 (Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @part) +5 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broader Monarch Money library/CLI centered on transaction search, transaction categorization, account listing, budgets, and authentication. However, this specific code chunk is narrowly focused on budget-domain APIs: budgets, budget amount updates, goals CRUD, cash flow, and bills. It does not implement transaction search, transaction recategorization, account listing, or authentication in the supplied code. It also includes capabilities not explicitly mentioned in the description, namely goal management, cash flow summary/analysis, and bills tracking. While budget management aligns partially with the description, the represented capabilities do not accurately match this code chunk's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description emphasizes transaction search, categorization, accounts/budgets listing, and authentication. The supplied code chunk does not implement transaction lookup, category updates, account listing, budget management, or auth. Instead, it accesses a different functional area: insights and profile-style data such as net worth, credit score, notifications, and subscription details, plus dismissing insights. These are materially different capabilities from the declared purpose, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes searching transactions, updating categories, listing accounts and budgets, and managing authentication. This file implements materially broader write capabilities: creating manual transactions and permanently deleting transactions, which are not mentioned in the stated skill description or suggested use cases.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The interface includes a deleteAllTransactionRules operation, which is an account-wide administrative action far broader than the stated use case. If an agent or integration invokes it accidentally or under prompt manipulation, all automation rules could be removed at once, disrupting categorization and financial workflows across the account.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This implementation performs bulk deletion of all transaction rules with no scoping, review step, or secondary approval. Because rules may control automated categorization and recurring workflow behavior, a single invocation can cause widespread integrity loss and hard-to-reconstruct account configuration damage.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This debug log emits the full authentication payload, which includes the user's password and, when MFA is enabled, a live TOTP code. Secrets in logs are highly sensitive because they may be exposed to local users, centralized logging systems, CI output, crash reports, or support bundles; in an authentication library, that materially increases credential-compromise risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: minimatch==3.1.2 — 3 advisory(ies): CVE-2026-27904 (minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu); CVE-2026-26996 (minimatch has a ReDoS via repeated wildcards with non-matching literal in patter); CVE-2026-27903 (minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==3.14.2 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: flatted==3.3.3 — 2 advisory(ies): CVE-2026-32141 (flatted vulnerable to unbounded recursion DoS in parse() revive phase); CVE-2026-33228 (Prototype Pollution via parse() in NodeJS flatted)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/TROUBLESHOOTING.md (reported line 152)May include surrounding context.

Solution:

bash
# Remove session file
rm ~/.mm/session.json

# Re-authenticate
monarch-money auth login

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares access to environment variables containing banking credentials and necessarily uses network access to a financial service, but it does not explicitly constrain or disclose tool scope via permissions or allowed-tools. In an agent setting, missing scope boundaries increases the chance of overbroad execution, secret access, or unintended outbound requests involving highly sensitive financial data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to provide an email, password, and MFA seed secret for a financial account, but it does not warn that these are extremely sensitive credentials or explain the risks of storing or exposing them. In this context, compromise of the MFA secret plus password can enable persistent unauthorized access to a user's financial data and account actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function accepts sensitive credentials and invokes login with saveSession: true, which persists authentication state to disk. While there are code comments about loading sessions, there is no confirmation prompt, user-facing log, or warning comment near the credential handling and session persistence to disclose that login data will be stored locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI explicitly supports passing the account password via the --password command-line flag and even prints usage guidance that encourages this pattern. Command-line arguments are commonly exposed through shell history, process listings, job control logs, and system monitoring tools, which can leak Monarch credentials to other local users or logging systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs a write operation by updating transaction splits through the API, which can alter financial record categorization and notes. Although there is a preview and optional dry-run mode, there is no explicit confirmation prompt or clear warning immediately before the irreversible update occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The update command modifies transaction category and/or notes via an API call, altering persisted user financial metadata. The code shows spinner/status messages but no pre-action warning or confirmation before applying the change.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This command updates a transaction's category through a write operation to the backend. It reports success afterward, but does not disclose or confirm the data-changing action before executing it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The create command sends a request that creates a new transaction record, which changes user financial data. Although the command description says 'Create a manual transaction', there is no confirmation prompt or explicit warning at the point of execution about the irreversible account-data change.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest describes capabilities around transactions, categories, accounts, budgets, and authentication. This CLI also registers receipts, doctor, and test commands, which are not mentioned in that stated scope and indicate additional behavior beyond the manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes the skill as focused on Monarch Money budget management, searching transactions, updating categories, listing accounts and budgets, and managing authentication. This file adds broader account-administration capabilities such as creating manual accounts, modifying account attributes and balances, deleting accounts, and triggering refreshes, which materially exceed the described read/list/categorize budget workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The method signatures accept start and end dates and the surrounding comments suggest balance/history retrieval, but getBalances ignores the requested date range and returns each account's current balance with today's date. Similarly, getHistory performs a recent-balances query but then discards it and returns a single current-balance point, contradicting the apparent intent conveyed by the method naming and comments.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cli/commands/test.ts:46

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
cli/commands/auth.ts:24

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
lib/client/MonarchClient.ts:124