Back to skill

Security audit

Expense Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a local personal expense tracker whose file access and ledger updates match its stated purpose, though users should be careful with deletion and correction commands.

Install only if you are comfortable with a local AI skill creating, editing, and deleting entries in its own expenses/ledger.json file. Keep backups if the ledger matters, and confirm delete or correction requests carefully.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code is local-only and writes spending data to a local JSON ledger, which aligns with the privacy/local-storage claim. However, the described functionality is materially broader than the supplied code. This script only accepts positional CLI arguments ( [date] [notes]), validates them, creates/updates a local ledger.json file, assigns an ID, and appends the entry. There is no natural-language interface, no handling of examples like 'spent $45 at Costco' or bill-splitting, no automatic categorization, no budget tracking or alerts, and no reporting logic. Because the actual primary behavior is a basic manual expense-entry utility rather than the fuller AI budgeting assistant described, this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code is narrowly focused on budget monitoring for a given month. It reads local ledger and budget files, aggregates spend by category, reports status against thresholds, and signals alerts via exit code. This is consistent with one subset of the description—local budget tracking and alerts—but it does not implement the core advertised functionality of natural-language expense capture, AI logging, splitting expenses, or auto-categorization. The code also does not show weekly/monthly reporting features beyond a current-month budget summary. Because the declared description presents a broader primary purpose and key capabilities that are absent from the code chunk, this is a meaningful description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a full expense-tracking assistant whose core functionality is capturing spoken/text spending entries, categorizing them, monitoring budgets, and producing alerts/reports, all locally. The supplied code chunk only implements a read-only query tool over an existing local ledger.json file. It filters by date, category, and vendor and formats output as summary/detail/json. While the 'runs entirely local' claim is consistent with the code, the primary purpose and major advertised capabilities are not represented in this chunk. This is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README emphasizes ease of use and local storage but does not clearly warn users that the skill can alter and delete entries in the local ledger. Because the skill supports corrections, recategorization, and deletion through conversational commands, users may not appreciate that normal language can result in irreversible or hard-to-notice changes to personal financial data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README encourages extremely broad, natural-language invocations like everyday spending statements without describing strict trigger boundaries or confirmation requirements. In an ambient or multitool agent setting, ordinary conversation could be misinterpreted as a command, leading to unintended creation, modification, or deletion of local financial records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly supports deleting, modifying, and recategorizing local financial records, but the description does not clearly warn users that conversational commands can alter or remove ledger data. In a finance context, undocumented destructive actions increase the chance of accidental integrity loss, especially when natural-language commands like 'cancel that last expense' or 'delete expense #12' may be triggered unintentionally or misunderstood.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.