Back to skill

Security audit

Expense Tracker Daily

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local expense tracker, but its instructions can lead an agent to place user-provided expense text into shell commands unsafely.

Install only if you are comfortable with a local JSON expense ledger in your home directory and with the current command-invocation risk. Avoid recording descriptions that contain shell syntax, quotes, semicolons, backticks, or command substitutions unless the skill is updated to pass all dynamic values as separate process arguments rather than a shell string.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:64
Finding

Shell Command Injection Through User-Controlled Expense Fields

Content
View full analysis
[options] ``` ### Technical Analysis The skill instructs the agent to extract the amount, category, description, and date from unrestricted natural-language input and insert those values into a shell command. The description is placed between double quotes, but the instructions do not require shell escaping, validation, or execution through an argument-array API. Double quotes alone do not safely isolate attacker-controlled shell input. A malicious description containing a double quote can terminate the intended argument, after which shell separators or substitutions can introduce additional commands. For example, if the extracted description were: ```text lunch"; id > /tmp/expense-skill-proof; # ``` naive interpolation would produce: ```bash python ".../expense_tracker.py" add --amount 35 --category other --desc "lunch"; id > /tmp/expense-skill-proof; #" --date 2026-04-09 ``` If the agent executes this generated string through a shell, the shell runs both the legitimate expense-tracker command and the injected `id` command. The Python script itself does not invoke a shell; the vulnerability is in the skill-level command-construction instructions. ### Attack Path 1. An attacker submits a natural-language expense request containing shell syntax in the description or another interpolated field. 2. The agent extracts that attacker-controlled text according to the skill instructions. 3. The agent inserts the text into the documented command template without robust shell quoting. 4. A crafted double quote terminates the intended ` ...[truncated 1105 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
# expense-tracker-daily

> OpenClaw 智能记账 Skill — 用自然语言记账,AI 自动分类,多维度统计分析。

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码的核心领域与声明一致,确实是一个支出/记账工具,并提供记录、查询、删除和统计功能,因此不存在完全不同主用途的问题。但声明中的关键能力“自然语言输入”和“自动分类”并未在代码中实现:add 命令必须显式传入金额等参数,description 也没有被用于关键词匹配分类;虽然定义了 CATEGORY_KEYWORDS,但仅在 categories 命令中返回预览,没有实际分类逻辑。此外,代码会在本地 ~/.qclaw/workspace/expense-tracker-data 下读写账本数据,这属于合理的实现细节,不构成严重越权,但确实表明它是数据引擎而非完整的自然语言助手。因此应判定为描述与实际行为存在明显不符。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents the skill entirely as a Chinese-only interaction model, including the core usage instruction to speak to the AI in Chinese examples, but does not mention optional language support or a justified region-specific limitation. This can violate language/locale policy requirements when users are not given an explicit choice or opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

该 markdown 文件定义了技能触发条件,适用 SQP-1。描述中将“花钱”“消费”“账单”等常见日常表达直接作为触发意图,且未提供排除条件或负例,容易与普通聊天、新闻讨论或泛泛理财对话重叠,导致误触发。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 适用于所有文件类型。当前描述全文以“智能记账助手”中文能力与中文示例为唯一交互方式,未说明可根据用户语言切换,也未提供语言/locale 选择,构成潜在的语言策略限制。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script stores personal financial records in a predictable local file under the user's home directory without any consent notice, privacy warning, or file-permission hardening. In the context of an expense tracker, this data is sensitive and may reveal habits, locations, purchases, and other personal information if the host account or filesystem is shared or backed up insecurely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes support for natural-language inputs like '午饭花了35' with automatic categorization. In the actual add flow, the record category is taken directly from args.category or defaults to '其他', and no logic uses CATEGORY_KEYWORDS to infer a category from the description text.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

cmd_delete removes matching records from the persisted expenses list and writes the modified dataset back to disk immediately. There is no confirmation prompt, cautionary message, or explicit documentation warning users that deletion is destructive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all user-facing category labels and descriptions exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language usage instructions and command help text are presented in Chinese, with no indication that other languages are supported or that the locale is intentionally constrained. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.