Back to skill

Security audit

Subscription Manager Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local subscription tracker, but its cancellation wording may mislead users into thinking real paid subscriptions are cancelled when only local records are changed.

Install only if you understand this manages a local tracker, not your actual accounts. Treat 'cancel' as 'mark cancelled/remove from my records' and separately cancel with the provider. Be careful opening CSV exports in spreadsheets if subscription names, notes, or URLs came from untrusted text.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/manager.py:359
Finding

CSV Formula Injection Through Unescaped Subscription Fields

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README presents commands and natural-language examples like 'Cancel my Hulu subscription' and 'python scripts/manager.py remove --name "Netflix"' without clearly stating that these actions only remove the local tracking entry and do not cancel the real subscription with the provider. In a financial-management skill, this can mislead users into believing a paid service has been terminated, causing continued billing, missed renewals, and financial loss.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises file-backed functionality and explicitly references local JSON storage plus a required script, but it declares no tool scope or allowed-tools constraints. In an agent environment, that means the skill can end up with broader file read/write capability than users or reviewers expect, increasing the chance of unintended modification or exposure of local data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation triggers are broad enough to activate on general budgeting, service-cost, or cancellation conversations, not just clear subscription-management requests. Over-broad auto-invocation can cause the agent to read or write subscription data in contexts where the user did not intend to use this skill, creating privacy and integrity risks through mistaken activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The primary command trigger "track subscriptions" is relatively generic and does not encode any explicit scoping or confirmation requirements, which can cause the skill to activate in unintended contexts. In a finance-related skill, accidental activation can expose or process sensitive spending and subscription data when the user did not intend to invoke this capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code path removes a subscription from the stored dataset and writes the change back to disk immediately when --permanent is used. Although it prints a message after deletion, there is no prior confirmation prompt or explicit warning at the point of execution for this irreversible local data loss operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.