Back to skill

Security audit

SmartBill Invoicing

Security checks for vulnerabilities and agentic risk

Overview

This SmartBill invoicing skill is mostly coherent, but it can send real SmartBill credentials and invoice data to an arbitrary configured API endpoint.

Review before installing. Use only with trusted environment variables and do not set SMARTBILL_API_BASE or pass --base-url unless you have verified the endpoint. Avoid SMARTBILL_DEBUG with real customer or invoice data because it prints full payloads and responses to stderr, which may be captured in logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/smartbill_cli.py:59
Finding

SmartBill Credentials Can Be Transmitted to an Arbitrary Configurable Endpoint

Content
View full analysis
Tuple[Any, Dict[str, str]]: url = f"{self.config.base_url}{path}" if query: compact_query = {k: v for k, v in query.items() if v is not None} if compact_query: url = f"{url}?{urlencode(compact_query)}" payload: Optional[bytes] = None if json_body is not None: payload = json.dumps(json_body).encode("utf-8") for attempt in range(self.config.retries + 1): headers = { "Authorization": self._auth_header, "Accept": accept, } ``` ### Technical Analysis The CLI permits the API destination to be supplied through either `--base-url` or the `SMARTBILL_API_BASE` environment variable. The value is accepted without validating its scheme, hostname, port, or relationship to the legitimate SmartBill service. The client subsequently constructs an HTTP Basic authorization value from the SmartBill username and API token and attaches it to every request sent to the configured destination. Base64 encoding is normal for HTTP Basic authentication and does not protect the ...[truncated 1864 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/smartbill_cli.py:140
Finding

Debug Logging Exposes Complete Invoice and API Response Data

Content
View full analysis
" print(json.dumps({ "smartbill_response": { "status": response.status, "headers": response_headers, "body": response_body_log, } }, ensure_ascii=False), file=sys.stderr) ``` ```python # --- error response debug log --- if self.config.debug: try: error_body_log: Any = json.loads(error_body.decode("utf-8")) except Exception: error_body_log = error_body.decode("utf-8", errors="replace") print(json.dumps({ "smartbill_response": { "status": exc.code, "headers": error_headers, "body": error_body_log, } }, ensure_ascii=False), file=sys.stderr) ``` ### Technical Analysis The code correctly excludes the `Authorization` header from request debug output. However, it records complete reque ...[truncated 2309 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Tainted flow: 'request' from os.getenv (line 156, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The CLI allows the SmartBill API base URL to be overridden from command-line arguments or the SMARTBILL_API_BASE environment variable, then sends Basic-authenticated requests to that URL. In an agent setting, tainted environment or prompt-influenced arguments could redirect credentials and invoice data to an attacker-controlled endpoint, causing credential exfiltration and unintended outbound data transfer.

Content

Scanner excerpt · scripts/smartbill_cli.py (reported line 158)May include surrounding context.

python
request = Request(url=url, data=payload, headers=headers, method=method)
            try:
                with urlopen(request, timeout=self.config.timeout_seconds) as response:
                    response_body = response.read()
                    response_headers = dict(response.headers.items())

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/smartbill_cli.py (reported line 434)May include surrounding context.

python
Two controls are applied in combination:

    1. Must have a .pdf suffix — prevents overwriting files that can never
       legitimately be PDFs (/etc/passwd, ~/.ssh/authorized_keys, …).
    2. Must resolve within an OpenClaw-allowed media root or the current
       working directory — prevents a prompt-injected agent from writing to
       arbitrary locations (e.g. ~/.ssh/authorized_keys.pdf) even when the

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/smartbill_cli.py (reported line 437)May include surrounding context.

python
Two controls are applied in combination:

    1. Must have a .pdf suffix — prevents overwriting files that can never
       legitimately be PDFs (/etc/passwd, ~/.ssh/authorized_keys, …).
    2. Must resolve within an OpenClaw-allowed media root or the current
       working directory — prevents a prompt-injected agent from writing to
       arbitrary locations (e.g. ~/.ssh/authorized_keys.pdf) even when the

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/smartbill_cli.py (reported line 434)May include surrounding context.

python
Two controls are applied in combination:

    1. Must have a .pdf suffix — prevents overwriting files that can never
       legitimately be PDFs (/etc/passwd, ~/.ssh/authorized_keys, …).
    2. Must resolve within an OpenClaw-allowed media root or the current
       working directory — prevents a prompt-injected agent from writing to
       arbitrary locations (e.g. ~/.ssh/authorized_keys.pdf) even when the

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill exposes meaningful capabilities including environment access, local file read/write, and outbound network access, but it does not declare an explicit tool scope or permissions boundary. That creates ambiguity for the agent runtime and reviewers, increasing the risk of over-broad execution, unintended credential access, or file/network operations beyond what is necessary for invoicing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.