Back to skill

Security audit

Family Finance Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local family-finance calculator that asks for sensitive financial details but does not show evidence of storing, transmitting, or modifying them.

Before installing, treat any household income, asset, liability, insurance, and family-member details as sensitive. Prefer using approximate values or omitting names unless needed, and expect most responses from this version to be in Chinese despite bilingual metadata.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill metadata does not declare any tool restrictions or permissions, yet static analysis indicates network-capable code exists elsewhere in the skill. For a finance-oriented skill handling sensitive household income, assets, liabilities, and insurance data, undeclared network access increases the risk of silent data transmission or unexpected external dependencies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The operational instructions for the skill are presented in Chinese, which effectively forces a specific language for use. There is no statement that users may interact in other languages, no opt-in for Chinese, and no documented reason that the skill must be Chinese-only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill solicits highly sensitive personal and financial information, including family member identities, ages, income, assets, liabilities, and insurance coverage, but provides no privacy warning, minimization guidance, or handling notice. In this context, users may disclose enough information for profiling, identity correlation, or financial harm without understanding the sensitivity of what they are sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code generates user-facing milestone descriptions and investment advice entirely in Chinese string literals. Because the skill does not offer a language selection or document a justified locale restriction, it violates the language/locale policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Risk assessments in the savings planner are returned only in Chinese, with no opt-in or fallback for other languages. This is a natural-language locale policy issue because the skill imposes a specific language on all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The recommendation titles, reasons, and budget considerations are all emitted in Chinese, but the file contains no mechanism for user language choice. That forces a single language/locale in user-visible output and falls under the policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This function builds multiple user-facing warnings, mitigations, and action items entirely in Chinese. With no explicit locale setting or opt-in, the skill enforces a single language and creates a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The summary, labels, strengths, concerns, and action-plan text are all user-visible Chinese strings. Because the code does not provide language choice or a documented reason for a Chinese-only experience, this is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These helper functions produce additional end-user recommendation text exclusively in Chinese. The lack of user opt-in or documented locale scope means the skill consistently forces one language across generated advice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This Python file contains hard-coded Chinese-language names and goal labels in request payloads, implying the skill is exercised in a single language/locale by default. There is no indication that users can opt into this locale or that the constraint is documented as region-specific, which fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code contains natural-language comments such as Chinese-only labels (e.g. 操作类型, 收入稳定性, 风险偏好) while the rest of the file uses English identifiers and values. Because the skill does not document a language choice or opt-in, it imposes a mixed language/locale experience that may conflict with language policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The sample request includes non-English names and goal labels such as "示例家庭", "爸爸", and "妈妈", which suggests the skill may be oriented toward a specific language/locale. In this file, there is no user opt-in, language selection, or justification that the skill is intended only for a Chinese-speaking region, so it risks violating the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest lists supported languages as both English and Chinese on L08, but the user-facing description on L04 is written only in Chinese. This can indicate a language/locale policy issue because the skill presents itself in a specific language without an explicit opt-in or clear bilingual presentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.