Back to skill

Security audit

Personal Finance Tracker

Security checks for vulnerabilities and agentic risk

Overview

This finance-tracking skill is purpose-aligned and local-first, with some implementation risks users should understand before analyzing sensitive CSVs.

Install only if you are comfortable using a local finance helper for user-provided CSVs. Do not provide credentials, account numbers, or full statements unless you intentionally choose to, and be cautious with CSVs from untrusted sources because crafted merchant names could distort terminal output. Confirm before enabling continuity memory or creating the local finance folder.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
cashflow_rollup.py:27
Finding

Terminal Escape-Sequence Injection Through Cashflow Report Fields

Content
View full analysis
= 0: months[month]["in"] += amount else: spend = -amount months[month]["out"] += spend categories[category] += spend merchants[merchant] += spend ``` ```python print("\nTop categories") for name, value in sorted(categories.items(), key=lambda item: item[1], reverse=True)[:5]: print(f"- {name}: {value:,.2f}") print("\nTop merchants") for name, value in sorted(merchants.items(), key=lambda item: item[1], reverse=True)[:5]: print(f"- {name}: {value:,.2f}") ``` ### Technical Analysis The `merchant` and `category` fields are read from a user-supplied CSV and used as dictionary keys without validation. When the report is generated, these values are interpolated directly into terminal output. Calling `.strip()` only removes leading and trailing whitespace. It does not remove embedded newlines, carriage returns, ANSI escape sequences, OSC sequences, or other C0/C1 control characters. A crafted field can therefore alter the terminal display, overwrite or conceal preceding output, create misleading report lines, or invoke terminal-specific features. The Python formatting operation does not execute shell commands directly. More consequential effects, such as clipboard manipulation or interactive links, depend ...[truncated 1312 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
recurring_scan.py:27
Finding

Terminal Escape-Sequence Injection Through Recurring-Charge Merchant Names

Content
View full analysis
= 0: continue merchant = (row.get("merchant") or "unknown").strip() raw_date = (row.get("date") or "").strip()[:10] if not raw_date: continue try: date = datetime.fromisoformat(raw_date) except ValueError: continue groups[merchant].append((date, -amount)) ``` ```python for merchant, items in sorted(groups.items()): if len(items) < 2: continue items.sort() gaps = [(items[i][0] - items[i - 1][0]).days for i in range(1, len(items))] amounts = [value for _, value in items] avg_gap = sum(gaps) / len(gaps) cadence = None if 25 <= avg_gap <= 35: cadence = "monthly" elif 330 <= avg_gap <= 380: cadence = "annual" if cadence and similar_amounts(amounts): found += 1 print( f"- {merchant}: {cadence}, {len(items)} charges, " f"avg {sum(amounts) / len(amounts):,.2f}" ) ``` ### Technical Analysis Merchant names originate in an untrusted transaction CSV and are printed directly when the script detects a recurring pattern. The only transformation is `.strip()`, which does not neutralize embedded terminal control sequences. An attacker can provide at least two crafted transactions with suitable dates and similar negative amounts so that the malicious merchant group satisfies the recurring-charge checks. Once the group is classified as monthly or annual, its merchant name is written verbatim to standard output. Embedded newlines c ...[truncated 1631 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code does align with part of the description: it imports a CSV of transactions and performs a cashflow review by summarizing inflows, outflows, monthly totals, and top spending areas. However, the declared description materially overstates the implemented functionality. There is no logic for detecting recurring bills, no debt analysis or prioritization, and no asset/liability aggregation for net worth snapshots. The primary behavior is a transaction CSV cashflow summary tool, which is only a subset of the declared purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup text instructs activation for a wide range of common finance-related intents such as budgeting, expense tracking, debt, subscriptions, and CSV analysis without defining clear boundaries or disambiguation criteria. That can cause the skill to trigger too often, leading to unnecessary collection or persistence of sensitive financial context and increasing the chance the agent applies finance workflows in contexts where they were not explicitly requested.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.