Back to skill

Security audit

phoenixclaw-ledger

Security checks for vulnerabilities and agentic risk

Overview

This finance-tracking skill is purpose-aligned and not malicious, but it needs Review because it passively scans conversations and payment screenshots, then stores and republishes detailed financial records automatically.

Install only if you are comfortable with a passive finance plugin reading money-related conversations and payment screenshots, creating local ledgers and receipt files, and embedding summaries into journals and scheduled reports. Review or disable cron jobs, screenshot auto-recording, journal export, cross-plugin sharing, and raw ledger/report locations if you need tighter privacy.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises zero-effort automatic extraction from conversations and payment screenshots but does not present a clear, prominent warning that sensitive financial data will be parsed, persisted, and exported into journal files. In a financial-tracking context, lack of informed consent is especially dangerous because users may unknowingly expose account activity, merchants, amounts, and behavioral spending patterns to long-term storage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation scope is extremely broad, triggering on essentially any mention of money or spending in any language and on payment screenshots. Because the skill passively extracts and stores financial data, this can cause collection of sensitive transaction information without sufficiently specific user intent or contextual confirmation, increasing privacy and overcollection risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill stores extracted transaction data in persistent local files, creating a durable record of sensitive financial information including amounts, merchants, categories, and timestamps. Persistence itself is expected for a ledger, but without clear minimization, retention limits, access controls, or encryption guidance, compromise of the host or related plugins could expose detailed financial history.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
3. **Extract Data**: Parse amount, merchant, category, timestamp
4. **Categorize**: Apply rules from `references/merchant-category-map.md`
5. **Deduplicate**: Prevent double-counting same transaction
6. **Store**: Write to `~/PhoenixClaw/Finance/ledger.yaml`
7. **Export**: Generate journal section using `assets/daily-finance-section.md`

## Explicit Triggers

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This template is designed to render highly sensitive financial data, including transaction descriptions, income sources, recurring expenses, and spending patterns, but it provides no privacy notice, minimization guidance, or access-control expectations. In a conversational finance skill that auto-detects expenses and processes payment screenshots, this increases the risk that users or downstream systems store and display personally sensitive financial information more broadly than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The attachment section explicitly references stored receipt screenshots and a raw ledger data file, which are likely to contain sensitive personal and financial information. Linking to raw data without any warning, redaction guidance, or permission boundary can expose complete transaction histories and payment artifacts to unintended viewers or systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file is designed to contain a static snapshot of detailed financial history, including dates, merchants/descriptions, categories, amounts, and payment sources. Storing and presenting that data in a broadly readable Markdown artifact without any access-control, minimization, or privacy warning increases the risk of unintended disclosure through local file browsing, sync, backups, screenshots, or other skill/plugin access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/category-rules.md (reported line 199)May include surrounding context.

Custom Categories

Users can create custom categories:

yaml
# ~/.phoenixclaw/config.yaml

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is described as 'passive' while the document immediately introduces active scheduled processing and automated report generation. This mismatch can mislead users or reviewers about the true operational scope, reducing informed consent and causing underestimation of the privacy and persistence risks associated with financial data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The daily workflow describes automatic extraction of financial data from conversations and screenshots and inclusion of a financial summary in journals, but provides no user-facing warning about handling highly sensitive personal financial information. In this context, silent automated processing of screenshots and conversation content raises meaningful privacy and confidentiality concerns.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file documents scheduled autonomous behavior that goes beyond a purely passive finance-tracking skill: it sets up recurring report generation, journal embedding, and persistent writes to user storage. In a financial plugin, this expansion materially increases data processing and retention of sensitive information without clear consent boundaries, making the documented behavior security-relevant rather than just operational guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The monthly cron setup instructs the system to generate detailed financial reports and save them to disk, but does not warn that sensitive summaries and spending patterns will be persistently stored. Persistent storage of personal financial analytics increases exposure risk from local compromise, backups, accidental sharing, or overly broad file access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The weekly report setup writes financial summaries to files and also embeds them into Sunday journal entries without clearly warning the user that sensitive data will be duplicated across multiple persisted locations. This increases the attack surface and the chance of unintended disclosure because the same financial information becomes available in both reports and broader journal artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document enables cross-plugin sharing of financial insight data via share_with_core: true and explicitly references sharing mood, goals, and growth-map data between plugins, but there is no clear user-facing warning or explicit consent flow described here. Because this skill processes sensitive financial and behavioral data, silent default sharing expands data exposure and can lead to privacy violations or unintended profiling across the broader PhoenixClaw ecosystem.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow explicitly allows high-confidence screenshots to be auto-recorded without an explicit confirmation or consent step. Because payment screenshots contain sensitive financial and contextual personal data, automatic ingestion can create privacy violations, incorrect ledger entries, and user surprise if screenshots are misclassified or OCR is wrong.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This reference defines patterns and templates for retrieving and presenting detailed financial information, including merchant history, transaction lists, dates, and amounts, but it provides no privacy guardrails, consent requirements, or minimization guidance. In a financial tracking skill, that omission can lead the agent to disclose sensitive spending data too broadly in response to casual prompts or in shared-device/session contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file states that expenses are detected from conversation text and repeatedly labels entries as sourced from conversation, which implies processing potentially sensitive personal and financial information. The markdown does not include any warning about privacy implications, consent, or careful handling of extracted financial details.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The variable examples and sample outputs consistently use yen symbols and formatting, which can imply a fixed locale or currency convention. Because the file does not state that the template is region-specific or allow user selection of locale/currency defaults, this may violate language/locale policy guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The template documentation presents the currency symbol as a fixed example of ¥ and all examples use China-specific payment platforms and formatting, which can imply a default locale-specific output. Because the file does not state that this template is region-specific or optional, it risks violating language/locale policy expectations for user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file includes multiple example goal phrases in Chinese, but does not indicate that language selection is configurable or optional. Under the policy, forcing or assuming a specific language without user opt-in can be a locale-policy issue even in documentation examples.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The mapping examples mix English and Chinese merchant names and keywords, but the document does not clarify whether these locale assumptions are optional, user-configurable, or intended only for a specific market. This can amount to a language/locale policy issue because the skill behavior may implicitly privilege certain languages without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

SQP-3 applies to natural-language policy issues in all file types. The document presents supported query patterns only for Chinese and English and gives no indication that language support is user-selectable or that the limitation is intentionally justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.