Back to skill

Security audit

Morning (Green Invoice)

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Morning/GreenInvoice helper that handles sensitive accounting actions, but its behavior is disclosed, scoped, and proportionate to that purpose.

Only install this if you want an agent to create or modify Morning/GreenInvoice business records using your API credentials. Provide language, currency, client, and document details explicitly for important accounting documents, and treat API secrets and JWTs as sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The guidance states 'Language: default to "Hebrew" unless the user specifies otherwise,' which imposes a specific language choice by default. The policy requires avoiding forced language or locale behavior unless the user is given a choice or the constraint is clearly justified.

Static analysis

No suspicious patterns detected.