Back to skill

Security audit

ezBookkeeping API Tools

Security checks for vulnerabilities and agentic risk

Overview

This skill is a functional ezBookkeeping API helper, but it exposes broader financial and session-management powers than its short description makes clear.

Review the full command list before installing. Use a least-privilege ezBookkeeping token, prefer HTTPS except for local-only testing, avoid broad home-directory .env files, and be careful because the skill can create financial records/configuration objects and list session metadata.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose understates the actual capabilities of the underlying tooling, which includes token/session listing and creation of additional finance objects beyond the described read/write transaction workflow. This mismatch can mislead users and reviewers into authorizing a skill with broader access than expected, enabling unintended disclosure of authentication material or unauthorized state changes in the bookkeeping system.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
sh scripts/ebktools.sh list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
sh scripts/ebktools.sh list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
sh scripts/ebktools.sh list

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ebktools.ps1 (reported line 749)May include surrounding context.

text
}

    if (-not $script:EBKTOOL_SERVER_BASEURL -or -not $script:EBKTOOL_TOKEN) {
        $envPath = Join-Path -Path $currentDir -ChildPath '.env'
        if (Import-DotEnvFile -Path $envPath) {
            if ($script:EBKTOOL_SERVER_BASEURL -and $script:EBKTOOL_TOKEN) {
                return

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ebktools.ps1 (reported line 1166)May include surrounding context.

text
}

    if (-not $script:EBKTOOL_SERVER_BASEURL -or -not $script:EBKTOOL_TOKEN) {
        $envPath = Join-Path -Path $currentDir -ChildPath '.env'
        if (Import-DotEnvFile -Path $envPath) {
            if ($script:EBKTOOL_SERVER_BASEURL -and $script:EBKTOOL_TOKEN) {
                return

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ebktools.sh (reported line 817)May include surrounding context.

sh
}

    if (-not $script:EBKTOOL_SERVER_BASEURL -or -not $script:EBKTOOL_TOKEN) {
        $envPath = Join-Path -Path $currentDir -ChildPath '.env'
        if (Import-DotEnvFile -Path $envPath) {
            if ($script:EBKTOOL_SERVER_BASEURL -and $script:EBKTOOL_TOKEN) {
                return

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Automatically loading credentials from the parent directory broadens the trust boundary and can cause the tool to silently consume secrets from unrelated directories. In multi-project or shared environments, this may result in unintended cross-context credential use against the wrong server or account.

Content

Scanner excerpt · scripts/ebktools.ps1 (reported line 759)May include surrounding context.

text
if (-not $script:EBKTOOL_SERVER_BASEURL -or -not $script:EBKTOOL_TOKEN) {
        if ($parentDir) {
            $envPath = Join-Path -Path $parentDir -ChildPath '.env'
            if (Import-DotEnvFile -Path $envPath) {
                if ($script:EBKTOOL_SERVER_BASEURL -and $script:EBKTOOL_TOKEN) {
                    return

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Automatically reading a .env file from the user's home directory creates an overly broad credential source and can silently apply global secrets to this skill. In an agent or automation context, this can lead to unintentional authenticated access to a personal finance server without the operator realizing which credentials were selected.

Content

Scanner excerpt · scripts/ebktools.ps1 (reported line 770)May include surrounding context.

text
if (-not $script:EBKTOOL_SERVER_BASEURL -or -not $script:EBKTOOL_TOKEN) {
        if ($homeDir) {
            $envPath = Join-Path -Path $homeDir -ChildPath '.env'
            if (Import-DotEnvFile -Path $envPath) {
                if ($script:EBKTOOL_SERVER_BASEURL -and $script:EBKTOOL_TOKEN) {
                    return

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ebktools.sh (reported line 597)May include surrounding context.

sh
home_dir="$HOME"

    if [ -z "$EBKTOOL_SERVER_BASEURL" ] || [ -z "$EBKTOOL_TOKEN" ]; then
        if load_env_file "$current_dir/.env"; then
            if [ -n "$EBKTOOL_SERVER_BASEURL" ] && [ -n "$EBKTOOL_TOKEN" ]; then
                return 0
            fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ebktools.sh (reported line 605)May include surrounding context.

sh
home_dir="$HOME"

    if [ -z "$EBKTOOL_SERVER_BASEURL" ] || [ -z "$EBKTOOL_TOKEN" ]; then
        if load_env_file "$current_dir/.env"; then
            if [ -n "$EBKTOOL_SERVER_BASEURL" ] && [ -n "$EBKTOOL_TOKEN" ]; then
                return 0
            fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ebktools.sh (reported line 613)May include surrounding context.

sh
home_dir="$HOME"

    if [ -z "$EBKTOOL_SERVER_BASEURL" ] || [ -z "$EBKTOOL_TOKEN" ]; then
        if load_env_file "$current_dir/.env"; then
            if [ -n "$EBKTOOL_SERVER_BASEURL" ] && [ -n "$EBKTOOL_TOKEN" ]; then
                return 0
            fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes shell-based execution paths but does not declare any tool scope or allowed-tools boundary. That omission weakens least-privilege controls and makes it harder for users or platforms to understand and constrain what the skill can execute, increasing the chance of unintended command execution or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs use of an API token and transmission of financial data to a server but provides no warning about the sensitivity of credentials or bookkeeping data. Users may supply secrets or regulated financial information without understanding the confidentiality and integrity risks, particularly if the configured base URL uses insecure transport or points to an untrusted host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Recommending storage of the API token in a .env file in the user's home directory without security guidance encourages insecure secret handling. Home-directory dotenv files are often world-readable due to permissive permissions, accidentally committed, backed up, or exposed to other local processes, leading to credential theft and subsequent access to financial records or administrative actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This PowerShell code reads EBKTOOL_TOKEN from environment variables and later uses it as a bearer token for outbound API requests. While the script does print the target URL before requests, it does not disclose that credentials from the environment or .env files will be used and sent to the server, which matches the missing-warning criterion for sensitive credential access and network transmission.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script exposes materially broader capabilities than the skill metadata describes, including creating accounts/categories/tags and querying session/token and server version information. This scope mismatch is dangerous because users or higher-level agents may grant trust based on the manifest while the implementation can perform additional sensitive actions on financial data and enumerate authentication-related metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The tokens-list command reveals all current-user sessions, including token identifiers, token types, user agents, and activity timestamps, which is unrelated to normal bookkeeping tasks. In an agent setting, this unnecessarily expands access into authentication/session reconnaissance and could aid account surveillance or follow-on abuse if exposed to an untrusted caller.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool performs remote POST operations that modify financial records and configuration objects without an interactive confirmation, dry-run, or safety prompt. In an agent context, this increases the chance of accidental or induced state changes to bookkeeping data from ambiguous prompts or automation mistakes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The tokens-list command enumerates active sessions for the current user, including token IDs, user agents, and last-seen metadata. That information is sensitive operational data unrelated to ordinary bookkeeping tasks and can aid account reconnaissance, session management abuse, or privacy leakage if exposed through an agent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script exposes powerful actions beyond the narrow bookkeeping-query/use scope implied by the skill metadata, including account creation, category creation, tag creation, and session/token listing. In an agent setting, this kind of scope expansion increases the chance of unintended state changes or sensitive data access because the tool surface is broader than users may reasonably expect from the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The help text explicitly permits an HTTP base URL such as http://localhost:8080, and the request code later sends the bearer token and financial query data to whatever base URL is configured without enforcing TLS. This enables credential and data exposure via interception or redirection when the tool is used against non-local or misconfigured endpoints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ebktools.sh (reported line 1123)May include surrounding context.

sh
if [ "$json_params" != "{}" ]; then
            if [ -n "$timezone_headers" ]; then
                response="$(curl -s -X "POST" \
                    -H "Authorization: Bearer $authToken" \
                    -H "Content-Type: application/json" \
                    -H "$timezone_headers" \

Static analysis

No suspicious patterns detected.