Back to skill

Security audit

OPC Invoice Manager

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local invoice-management skill, but it needs review because it can change financial records and generate customer-facing invoice documents without enough validation and output escaping.

Install only if you are comfortable with a local skill reading and writing your invoice, contract, client, and payment metadata. Review generated invoices and collection drafts before sending, keep the invoice directory protected, and avoid using untrusted contract or client-profile text until the templates escape HTML/Markdown and payment updates validate positive amounts and real dates.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
templates/invoice.html:108
Finding

Unescaped Stored Data in Generated HTML and Markdown Documents

Content
View full analysis
{{n}} {{description}} {{type}} {{quantity}} {{unit_price}} {{amount}} {{currency}}
Subtotal{{subtotal}} {{currency}} {{tax_name}} ({{tax_rate}}){{tax_amount}} {{currency}} Discount-{{discount_amount}} {{currency}} Total Due{{total_amount}} {{currency}}
Payment Instructions
{{payment_instructions}}
Notes
{{notes}}
``` The Markdown invoice uses the same direct interpolation pattern: ```markdown | {{n}} | {{description}} | {{type}} | {{quantity}} | {{unit_price}} | {{amount}} | ## Payment Instructions {{payment_instructions}} ## Notes {{notes}} ``` ### Technical Analysis The Skill automatically imports client, contract, invoice, and payment information and inserts those values directly into HTML and Markdown templates. Neither the templates nor the governing workflow require context-aware output encoding, HTML sanitization, or Markdown escaping. Fields such as `client_name`, `description`, `payment_instructions`, and `notes` can therefore alter the structure of generated documents. In HTML output, attacker-controlled value ...[truncated 1867 chars]
Remediation
View remediation
` elements, event-handler attributes, raw HTML, malicious Markdown links, table-breaking pipes, and multiline payloads. 9. Generate PDFs through a renderer configured to disable JavaScript, local-file access, and uncontrolled remote-resource loading. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/invoice_tracker.py:371
Finding

Payment Mutations Accept Invalid Amounts and Unvalidated Dates

Content
View full analysis
= total: entry["status"] = "paid" entry["paid_date"] = pay_date entry["outstanding_amount"] = "0" else: entry["status"] = "partial" if total: entry["outstanding_amount"] = str(total - total_paid) else: entry["status"] = "paid" entry["paid_date"] = pay_date entry["outstanding_amount"] = "0" ``` The command-line interface accepts the values as unrestricted strings: ```python parser.add_argument("--amount", type=str, default=None, help="Partial payment amount") parser.add_argument("--date ...[truncated 2371 chars]
Remediation
View remediation
Decimal("0")`. 2. Compare the payment against the current outstanding balance before recording it. 3. Reject excessive payments by default, or require an explicit overpayment workflow that records the resulting credit. 4. Parse `--date` with the existing ISO date parser and reject malformed or impossible dates. 5. Consider rejecting future payment dates unless the user explicitly confirms them. 6. Validate both loaded and mutated invoice records against the metadata schema. 7. Enforce numeric constraints in code even if equivalent schema constraints are added, because JSON Schema validation is not currently performed. 8. Detect duplicate payment records using invoice number, amount, date, and payment reference. 9. Perform mutations atomically and retain a transaction or change history so incorrect updates can be audited and reversed. 10. Add automated tests for negative, zero, excessive, malformed, duplicate, and cumulative partial-payment scenarios. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code only handles invoice/document numbering: loading and saving numbering configuration, reading an invoice index, generating the next sequential number, and validating uniqueness/format. While invoice numbering can be a supporting part of invoice generation, this code does not implement the declared end-to-end accounts receivable capabilities such as collections, reconciliation, aging analysis, or cash flow reporting. There are no triggers or permissions to contradict the description, but the primary purpose and capability scope are materially narrower than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code substantially matches several AR lifecycle functions: collections follow-up/action summaries, payment reconciliation via mark-paid and partial payments, aging analysis, overdue detection, and AR/revenue insights. However, the declared description says it manages the full billing lifecycle including invoice generation and contract-data integration, and those capabilities are absent from the supplied code. The script operates only on existing invoice metadata in a local invoices directory and updates/report on them. Because key declared capabilities are not implemented in this chunk, the description overstates what the code actually does.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
---

## Output Rules

- All reports in markdown
- File names use kebab-case

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description states that it auto-infers data from contracts and client profiles and later shows storage of client records and invoice metadata. Because this involves potentially sensitive business and personal contact information, the markdown should clearly warn users that the skill reads and persists such data locally so they can make an informed decision.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to read from and write to local files and to invoke local scripts, but it does not declare any explicit tool scope or permission boundaries. That creates an authorization ambiguity where the runtime may grant broader filesystem access than users or platform policy expect, increasing the chance of unintended data exposure or modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The mode-detection triggers are extremely broad terms such as 'invoice', 'send', 'find', and 'paid', which can cause the skill to activate sensitive workflows on incidental or ambiguous user text. In a system with file access and state-changing actions, that raises the risk of unintended invoice creation, collections actions, payment-state updates, or disclosure of customer financial records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The README says the skill generates ready-to-send email drafts and automatic overdue detection, implying customer-specific financial data will be used in outbound communication content. A brief warning would help users understand that invoice status and client details may be incorporated into drafts and should be reviewed before sending.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The HTML root sets lang="en", which fixes the document language to English. Under the stated policy, forcing a specific language without user opt-in or a documented region-specific reason is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.