Back to skill

Security audit

nl2ledger

Security checks for vulnerabilities and agentic risk

Overview

This bookkeeping skill is mostly coherent, but it can append financial records to an unconstrained user-supplied file path without validating the target ledger.

Review before installing. Use this only with a dedicated QianJi CSV file you trust, confirm the exact destination path before writes, and avoid opening exported ledgers in spreadsheet tools if notes or other fields may contain formula-like text. Set the recorder/account defaults for your own bookkeeping context.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/append_entry.py:56
Finding

Unrestricted File Append Through an Unvalidated Ledger Path

Content
View full analysis
0: with open(csv_file, "rb") as f: f.seek(-1, 2) needs_newline = f.read(1) != b"\n" with open(csv_file, "a", encoding="utf-8", newline="") as f: if needs_newline: f.write("\n") f.write(csv_line) ``` ```python parser.add_argument("--csv-file", required=True, help="Path to the CSV file") ``` ```python args = parser.parse_args() row, entry_id = build_row(args) csv_line = row_to_csv_string(row) append_to_file(args.csv_file, csv_line) ``` The associated Skill workflow permits a user-supplied path when automatic discovery fails: ```markdown Use Glob to find `QianJi_*.csv` in the project root directory. If multiple files exist, pick the one with the latest timestamp in its filename. If no CSV file is found, tell the user and ask them to specify the path. ``` ### Technical Analysis The `--csv-file` argument is passed directly into `os.path.getsize()` and `open()` without validating that the target: - Has a `.csv` extension. - Is a regular file rather than a symbolic link or special file. - Resides in an approved ledger directory. - Has the expected QianJi 18-column header. - Is actually the ledger presented to the user during confirmation. The script therefore accepts any existing path writable by its operating-system user. Python follows symbolic links by default, so a path that appeared to identify a ledger could also resolve to another writable target. This is not an operating-system privilege escalati ...[truncated 1649 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/append_entry.py:23
Finding

Spreadsheet Formula Injection in User-Controlled CSV Fields

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes a natural-language bookkeeping skill that understands expense phrases in Chinese/English and extracts item/amount information from free-form text. The supplied code does not implement any NLP, text parsing, or trigger handling. Instead, it is a low-level CSV append script that expects all fields such as time, category, amount, and accounts to be passed explicitly as command-line arguments. While appending to a QianJi CSV is consistent with part of the description, the primary behavior is materially narrower and different from the declared skill behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill performs file-writing behavior by appending entries to a ledger CSV, but it does not declare any explicit tool scope or permissions boundaries. That makes its write capability implicit rather than constrained, increasing the risk of unintended or overly broad file modification if the runtime grants access based on detected capabilities or defaults.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very common words like 'lunch', 'dinner', 'spent', '买了', and patterns resembling ordinary conversation, which can cause accidental activation. In this skill's context, accidental activation is more dangerous because the skill is designed to write financial records, so false triggers could lead to unwanted ledger modifications or confirmation prompts during unrelated chats.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file hard-codes the recorder identity to 小明 in the default values, which can silently attribute entries to the wrong person in shared or multi-user bookkeeping contexts. This is primarily an integrity and privacy issue rather than a code-execution risk, but it can cause misattribution of financial records and confusion in downstream accounting workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file appears to force a specific language for the skill documentation, beginning with a Chinese-only title and continuing with Chinese field names. Under the policy, language constraints should be optional or clearly justified; no opt-in or scope justification is provided here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.