Back to skill

Security audit

Bill Manager

Security checks for vulnerabilities and agentic risk

Overview

This bill-management skill is mostly a coherent template guide, but it asks users to record sensitive financial account identifiers without enough redaction or storage-safety guidance.

Review the templates before using them. Do not enter full bank account numbers, card numbers, credentials, PINs, security codes, or unredacted statement data; use account aliases or last four digits only, and store any exported bill records somewhere access-controlled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/bill-templates.md:202
Finding

Plaintext Collection of Full Financial Account Identifiers

Content
View full analysis

Vulnerability Details

File Location: references/bill-templates.md, lines 202 and 209
Vulnerability Type: Plaintext sensitive financial data collection
Risk Level: Medium

Vulnerable Code Snippet

text
Account Info: [Account Number]
text
[ ] Auto-debit    Debit Account: [Account]

Technical Analysis

The recurring-bill template asks users to enter an account number and debit account without requiring masking or limiting the value to a non-sensitive alias. Full financial account identifiers are unnecessary for bill organization; a user-defined account name or the last four digits would provide sufficient differentiation.

Because the Skill operates through conversational and document-based records, users following this template may place account identifiers in plaintext chat histories, logs, exports, backups, or copied tracking documents. The Skill provides no warning against entering complete account numbers and no guidance concerning redaction, secure storage, access control, or retention.

This is a data-minimization and sensitive-data-handling weakness. The audit found no mechanism that automatically transmits or exploits the information.

Attack Path

  1. A user invokes the recurring-bill management workflow.
  2. The Agent presents the template containing Account Info: [Account Number] or Debit Account: [Account].
  3. The user follows the template and supplies a complete financial account identifier.
  4. The identifier is retained in plaintext within conversation history, platform logs, exports, backups, or a copied bill-management document.
  5. An attacker or unauthorized person who later obtains access to those records recovers the identifier.
  6. The exposed information may be used for targeted phishing, social engineering, identity correlation, or financial-account reconnaissance.

Impact Assessment

Successful exploitation does not directly grant banking privileges, authorize payments, or expose credentials ...[truncated 353 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace full-account fields with masked, non-sensitive identifiers:
text
Account Alias: [e.g., Household Checking]
Account Identifier: [Last 4 digits only]
  1. Add an explicit warning adjacent to every financial identifier field:
text
Never enter a full bank or card number, PIN, password, security code,
authentication token, or online-banking credential.
  1. Apply the same minimization standard to related fields, including Receiving Account, Transaction ID, and any imported transaction records. Use aliases, truncated references, or redacted values wherever possible.

  2. Add privacy guidance covering:

    • Redaction before importing statements or receipts
    • Least-privilege access to exported records
    • Encryption for locally stored financial documents
    • Minimal retention and secure deletion
    • Avoidance of sensitive financial data in shared calendars or notes
  3. Revise the Privacy Note in SKILL.md so that it clearly distinguishes the Skill's lack of intentional third-party transmission from the possibility that conversation platforms may retain user-provided content.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger examples in the Usage section are short and generic, such as requests to record spending or bills, which can overlap with normal conversational requests and cause the skill to activate more broadly than intended. In a personal-finance context, unintended invocation could expose or solicit sensitive financial details when the user did not explicitly mean to use this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The budget-planning examples like 'How to save money' and 'Budget planning advice' are broader than the skill's stated scope of bill and expense management, so they may capture general financial-advice requests that should be handled elsewhere. This can lead to unintended invocation and overreach into adjacent financial domains, increasing the chance of misleading or inappropriate responses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README presents the assistant as responding in Chinese throughout its examples and title, while also showing English user prompts, but it does not state that users can choose their preferred language. This can be interpreted as a language-policy issue because the skill appears to default to Chinese output without explicit user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This section switches to Chinese content and recommends Chinese platforms, but the document does not tell users that responses may be localized or provide an opt-in language choice. That can violate language/locale policy expectations when a skill implicitly forces or defaults to a specific language or regional ecosystem.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file includes fields for payment account digits, transaction IDs, and invoice status, and elsewhere also requests account information for recurring bills. The templates describe collecting potentially sensitive financial data but do not include any warning or guidance about protecting, redacting, or securely storing that information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This file is a natural-language reference guide and presents all user-facing content in English only. Under the stated policy, forcing a specific language without user opt-in can be a locale or language policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The guide includes region-specific categories such as "Spring Festival" and "red envelopes" as part of its standard expense taxonomy, which can impose a particular cultural/locale framing without stating that these are examples or optional adaptations. Under the language/locale policy, locale-specific conventions should be clearly justified or offered as optional rather than presented as universally applicable defaults.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.