Back to skill

Security audit

银行对账单处理和转换(Bank statement processing and conversion)

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent bank-statement conversion purpose, but it automatically downloads and caches unauthenticated spreadsheet templates that can affect financial import files.

Install only after reviewing the template-download behavior. Prefer pre-provisioned, verified local templates, use an isolated non-privileged Python environment with pinned dependencies, avoid enabling cloud OCR for sensitive statements unless approved, and review generated spreadsheets before importing them into financial systems.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
scripts/core/template_manager.py:24
Finding

Remote Spreadsheet Templates Are Downloaded Without Integrity Verification

Content
View full analysis
Optional[str]: target_upper = (target_system or '').upper() if target_upper not in TEMPLATE_REGISTRY: logger.error(f"未注册的目标系统: {target_system}") return None info = TEMPLATE_REGISTRY[target_upper] template_dir = ensure_template_dir() local_path = os.path.join(template_dir, info['local_name']) url = info['url'] if os.path.exists(local_path) and not force: ...[truncated 4047 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:225
Finding

Untrusted Bank Statement Fields Can Become Formulas in Generated XLSX Files

Content
View full analysis
Any: """直接复制""" source_field = mapping.get('source_field') if source_field: return getattr(txn, source_field, None) return None ``` The default XLSX writer inserts these values directly into cells: ```python for row_idx, mapped_record in enumerate(mapping_result.mapped_records): excel_row = data_start_row + row_idx record = mapped_record.record for col_idx, field in enumerate(all_fields, 1): value = record.get(field, '') if isinstance(value, Decimal): value = float(value) if value is None: value = '' ws.cell(row=excel_row, column=col_idx, value=value) ``` The merged BIPV5 writer has the same behavior: ```python for col_idx, ...[truncated 3454 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:318
Finding

Dependency Installation Instructions Use Unpinned Package Versions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (40)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill clearly describes capabilities that read local files, write output files, and may fetch templates from the internet, but it declares no explicit tool scope or permission boundary. This creates an authorization gap: an orchestrator or reviewer cannot easily constrain or audit when filesystem and network actions are permitted, increasing the chance of unintended data access or exfiltration during statement processing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough that the skill may activate on loosely related mentions of bank statements, PDFs, SWIFT, or target systems, causing the agent to invoke a capability that reads and transforms sensitive local files in situations the user did not specifically intend. In a financial-document skill, over-broad activation increases the risk of unnecessary access to confidential files and accidental execution of network-enabled code paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that missing templates will be automatically downloaded from preconfigured internet locations, but does not prominently disclose this network behavior or its security implications in the operational description. Because the skill processes bank data, silent dependency retrieval expands the trust boundary and can expose users to supply-chain compromise, unexpected outbound connections, or use of unverified templates.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly allows swapping in cloud OCR providers for bank statement PDFs, which can transmit highly sensitive financial documents and extracted text to third-party services. In the context of bank statements, this materially raises confidentiality and compliance risk because account numbers, balances, counterparties, and transaction details may leave the local environment without strong controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains user-facing natural-language descriptions and CLI help text that assume Chinese as the required language. The policy forbids forcing a specific language or locale without user opt-in or a documented, justified regional constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code resolves missing template files by automatically downloading them from the internet during normal conversion. In a bank-statement processing skill, this creates a software supply-chain risk: a compromised remote source, MITM, or unexpected template change could inject malicious or untrusted content into generated files or influence downstream processing without explicit user approval. The financial-data context increases concern because outputs are intended for enterprise import workflows and may be trusted by operators.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Batch merge mode repeats the same risky behavior by resolving templates via local lookup with automatic internet download when absent. Because batch processing can handle many files at once, a malicious or tampered template could affect a larger volume of generated outputs in one run, amplifying the supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Argument descriptions, usage examples, errors, and conversion results are all emitted in Chinese, with no option for another language. This is a natural-language policy issue because the tool fixes the interaction language rather than letting the user choose or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file's natural-language docstrings and comments are written entirely in Chinese, including user-facing descriptive text, with no indication that language choice is optional or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module documentation explicitly describes fallback behavior that downloads template files from the internet when local assets are missing. In a banking-statement processing skill, this introduces an unnecessary external supply-chain and data-handling risk: remote content may be tampered with, replaced, or fetched from an untrusted endpoint, and the mapper becomes dependent on network-retrieved artifacts for financial data workflows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This helper delegates template resolution to code that may fetch a template over the network, adding external-access capability to a local transformation component. In the context of converting sensitive bank statements, pulling executable-format office templates from remote locations can expose users to supply-chain attacks, malicious file content, or integrity issues in downstream financial imports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The callable path exposes automatic internet retrieval behavior without clear user-facing disclosure at the point where it is invoked. For a skill handling bank statements and generating import files for treasury/accounting systems, hidden network activity materially increases risk because operators may assume processing is entirely local while sensitive workflows depend on remote resources.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This mapper can indirectly trigger network retrieval of a template via resolve_template('FINGARD'), even though its primary role is local data transformation. That expands trust boundaries from local file handling to remote content acquisition, creating supply-chain and SSRF-style risk if the download source or resolution logic is compromised, especially because the fetched file is later used to generate outputs consumed by financial systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module docstring states that if a local template is unavailable, the skill will automatically download one from an internet address and store it locally. The file also writes output XLS files, but there is no confirmation prompt and no explicit user-facing warning in the operational methods about the network retrieval or filesystem modifications these actions perform.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code comments and validate() logic imply that either debitamount or creditamount must be present, but those fields are not part of REQUIRED_FIELDS, so the special-case branch never executes. This allows structurally invalid or empty-value transactions to pass mapping validation, which can corrupt downstream imports, misstate cash movements, or weaken financial data integrity checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file documents and implements a fallback behavior where a missing local template may be automatically downloaded from the internet, but this code path has no explicit user confirmation, warning, or integrity enforcement visible here. In a financial statement conversion skill, silent remote retrieval of a template introduces supply-chain and trust-boundary risk: a compromised URL, tampered template, or unexpected network fetch could alter outputs or expose sensitive workflow metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The mapper’s documented template resolution flow allows missing local templates to be fetched automatically from an Internet source before use. In a skill that processes financial files and emits imported spreadsheets, this introduces a supply-chain trust boundary: a tampered remote template could alter workbook contents, formulas, or instructions without the user’s awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest/config uses Chinese natural-language descriptions, field labels, default values, and header aliases throughout, including target sheet name and status text, without indicating any user opt-in or locale selection. That can violate a language/locale policy when a skill implicitly assumes Chinese output or matching behavior for all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file uses Chinese for the module description and API docstrings/comments, but does not state that the skill is intended only for Chinese-speaking users or offer a language choice. That can violate a language/locale policy requiring user opt-in or explicit justification for a forced language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The OCR interface and default Tesseract backend hard-code the OCR language to "chi_sim+eng". This creates a language/locale policy issue because the skill enforces a specific language configuration by default and does not expose a user-facing choice or documented opt-in within this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README consists solely of a Chinese-language description and provides no indication that users may choose another language or locale. Under the policy, natural-language content that imposes a specific language without opt-in is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This reference file presents all user-facing natural-language content in Chinese, including the title and currency names, with no indication that the locale is optional or intentionally limited to a Chinese-speaking context. Under the policy rule for language/locale, this is a natural-language constraint that should either be optional or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The module docstring and the predefined matching vocabulary are written for Chinese banking statement headers, which indicates a language-specific skill behavior. The file does not state that this locale restriction is optional, user-selected, or explicitly limited to a China/Chinese-language banking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module description states that it converts currency codes to Chinese names, and the implementation returns Chinese currency labels only. This imposes a specific language/locale behavior without any visible opt-in or documented regional justification, which matches the language-policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language documentation that assumes a Chinese language locale, beginning with the module docstring and continuing throughout class and field descriptions. Under the policy, forcing a specific language without user choice or a documented justification is a locale-policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.