Back to skill

Security audit

Bookkeeping

Security checks for vulnerabilities and agentic risk

Overview

This bookkeeping skill is purpose-aligned and disclosed, but users should trust the local CLI dependency before installing because it handles and mutates financial records.

Install only if you are comfortable trusting the bookkeeping CLI source and any optional attachment plugin, because they will process local bill attachments and update a local financial database. Review imported files and be especially careful with reset, batch import, and dependency updates.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Mutable Third-Party Dependency Sources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:4; references/install.md:7-10; references/install.md:51-55
Vulnerability Type: Supply-chain risk through unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

SKILL.md:4:

yaml
metadata: {"openclaw":{"homepage":"https://github.com/lastarla/bookkeeping-agent","requires":{"bins":["bookkeeping"]},"install":[{"id":"brew","kind":"brew","formula":"lastarla/tap/bookkeeping-tool","bins":["bookkeeping"],"label":"Install bookkeeping (Homebrew, macOS)"},{"id":"pipx","kind":"pipx","package":"git+https://github.com/lastarla/bookkeeping-tool.git","bins":["bookkeeping"],"label":"Install bookkeeping (pipx from GitHub)"}]}}

references/install.md:7-10:

bash
brew install lastarla/tap/bookkeeping-tool

references/install.md:51-55:

text
如果上下文里没有本地路径、只有 Feishu 附件引用,再额外安装并启用 `@angli/openclaw-message-attachments` 作为下载 fallback。

推荐链路是:

1. 优先使用 OpenClaw 已落盘的本地 inbound 文件
2. 如果没有本地路径,再调用附件下载插件
3. 使用返回的本地路径执行 `bookkeeping import <file> --json`

Technical Analysis

The Skill recommends installing the bookkeeping executable from a custom Homebrew tap or directly from a mutable GitHub repository. The Git dependency does not specify an immutable commit hash or release tag. The optional attachment plugin is also identified without a fixed version, checksum, or signature-verification procedure.

These mutable dependency references cause the code ultimately installed or loaded by users to be determined by upstream state at installation time rather than by the reviewed Skill package. If an upstream repository, package publication account, Homebrew tap, plugin release, or maintainer account is compromised, malicious code could be distributed without any modification to this repository.

This finding does not establish that the named upstream projects are currently malicious. It identifies the absence of controls that bind ...[truncated 1552 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the pipx Git dependency to an immutable, reviewed commit:
    text
    git+https://github.com/lastarla/bookkeeping-tool.git@<full-commit-hash>
    
  2. Prefer signed, versioned releases over installation from a repository's mutable default branch.
  3. Pin the Homebrew formula to a reviewed version where supported, and ensure the formula verifies the downloaded artifact with a cryptographic SHA-256 checksum.
  4. Specify an exact reviewed version of @angli/openclaw-message-attachments rather than relying on the latest available release.
  5. Verify release signatures, checksums, repository ownership, and package provenance before recommending updates.
  6. Use automated dependency monitoring, but require security review before advancing pinned versions.
  7. Run the CLI and attachment plugin with least privilege, restricting access to unrelated files, credentials, and network destinations where the execution environment permits.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s natural-language instructions and reply rules are entirely specified in Chinese, including required user-facing behavior such as categories and response formatting. There is no indication that the user may choose another language or locale, which can violate a language/locale policy requiring opt-in rather than forcing a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire installation guide is written in Chinese, and the file does not offer an alternative language, user opt-in, or any statement that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user choice or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example uses a very broad trigger phrase ('帮我导入一下') tied to an uploaded file, which can cause the agent to perform a write action based on minimal confirmation. In a bookkeeping skill, imports modify persistent financial data, so ambiguous activation increases the risk of accidental or unintended state changes, especially when attachment context is auto-resolved to a local file path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The multi-attachment example ('这些帮我处理一下') is underspecified and could map to multiple sensitive operations, including import or duplicate-check workflows, based only on nearby files. Even though the doc says not to silently batch import, the trigger remains broad enough to encourage unsafe activation logic if implemented loosely, creating a risk of processing the wrong attachment or performing unintended actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The troubleshooting content is entirely written in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. This can violate a language/locale policy when a skill implicitly forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The quickstart content presents all user utterances and interaction patterns exclusively in Chinese, with no indication that users may choose another language or that the locale restriction is intentional. This can reflect a language policy constraint without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.