Back to skill

Security audit

Receipt Tracker

Security checks for vulnerabilities and agentic risk

Overview

This receipt-tracking skill mostly matches its stated purpose, but it also ships undisclosed Nextcloud/WebDAV code with embedded credentials and a plaintext endpoint.

Review before installing. The receipt-tracking behavior itself is understandable, but the package should remove or fully disclose the Nextcloud worker, rotate the exposed password, use user-provided secrets over HTTPS, and require clear consent before sending receipt images to an external model or retaining purchase history locally.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
nc_worker.py:8
Finding

Hard-Coded Nextcloud Credentials and Plaintext WebDAV Endpoint

Content
View full analysis

Vulnerability Details

File Location: nc_worker.py, lines 8–10
Vulnerability Type: Hard-coded credentials and insecure transport configuration
Risk Level: High

python
NC_URL = "http://fedora:8082/remote.php/dav" # Via proxy/internal network if available, or replace with real URL
USER = "receipts"
PASS = "yu9cZvCVtctkhg3!"

Technical Analysis

A reusable Nextcloud username and password are embedded directly in distributed source code. Any person or process able to read the project can recover these credentials without authentication. Secrets committed to source code may also remain available through package copies, caches, backups, and version-control history after removal.

The configured WebDAV endpoint uses plaintext HTTP rather than HTTPS. If the worker's planned WebDAV operations are implemented using these constants, authentication headers and private receipt data could traverse the network without transport encryption. An attacker with a suitable network position could observe or manipulate that traffic.

The relevant worker functions are currently stubs, so this artifact does not itself perform the network requests. Nevertheless, the exposed credentials can be used independently if the service is reachable, and the configuration creates an unsafe implementation path.

Attack Path

  1. An attacker obtains read access to the skill package or another copy of its source.
  2. The attacker opens nc_worker.py and extracts the Nextcloud URL, username, and password.
  3. If the fedora:8082 service is reachable from the attacker's environment, the attacker authenticates to the WebDAV endpoint with the exposed credentials.
  4. The attacker attempts operations permitted to the receipts account, potentially including listing, downloading, modifying, or deleting receipt files.
  5. Separately, once the planned WebDAV code is implemented, an attacker positioned on the relevant network path could intercept or tamper with plaintext HTTP tra ...[truncated 622 chars]
Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed password. Treat it as compromised even if the repository was intended to be private.
  2. Remove credentials from source code and all retained repository history, package archives, build artifacts, logs, and backups where feasible.
  3. Retrieve credentials at runtime from a dedicated secret manager or protected environment variables. Do not provide insecure fallback values.
  4. Replace the endpoint with an https:// URL and enforce TLS certificate and hostname verification. The application should fail closed when secure transport cannot be established.
  5. Use a dedicated service account with least-privilege access restricted to the exact receipt folder and required WebDAV operations.
  6. Prefer a short-lived application token over the account's primary password. Establish a regular rotation policy.
  7. Add secret scanning to pre-commit and CI pipelines to prevent credentials from entering future releases.
  8. Ensure implemented HTTP requests use explicit connection and read timeouts, reject redirects to untrusted or plaintext destinations, and avoid logging authorization headers or receipt contents.
  9. Audit Nextcloud access logs for use of the exposed account and investigate unexpected file access or modification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Описание частично совпадает с намерением кода: есть указания на обработку чеков, использование gemini-2.5-flash и сохранение в expenses.csv. Однако фактический фрагмент в основном представляет собой каркас интеграции с Nextcloud через WebDAV, включая получение файлов из удаленной папки и применение тегов, а это существенная возможность и используемый ресурс, не отраженные в заявленном описании. Кроме того, одна из ключевых заявленных функций — ежемесячные отчеты — в коде отсутствует даже на уровне заготовки отдельной функции. Поэтому описание не вполне точно отражает реальное поведение и интеграции кода.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to transmit receipt images to an external model/subagent for OCR and categorization without explicit user notice or consent. Receipts often contain sensitive information such as merchant names, purchase contents, timestamps, partial card data, addresses, or loyalty details, so undisclosed third-party processing materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill directs the agent to send receipt images to a subagent using a remote model, which is effectively network-capable behavior, but it declares no tool scope or allowed-tools restrictions. This weakens governance and reviewability because a user cannot easily see that external processing is required, and the runtime may permit broader-than-necessary capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill stores extracted receipt data in a persistent CSV database containing potentially sensitive personal purchase history, dates, and spending patterns, but it does not clearly warn the user about retention or local storage. This creates privacy risk because users may believe the processing is transient when the skill is actually building a lasting expense ledger.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill hard-codes Russian category labels and later defines reporting requests in Russian phrases, without offering a language choice or documenting a justified locale restriction. This can violate language/locale policy because it forces a specific locale behavior rather than allowing user preference.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file embeds a plaintext internal Nextcloud DAV endpoint and hardcoded credentials directly in source code. Any user with access to the skill code, logs, backups, or packaged artifact can recover these secrets and access remote files unrelated to the minimal local CSV receipt-tracking behavior described in the manifest, enabling unauthorized data access and lateral movement into an internal service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is designed to make authenticated network requests to an internal DAV service without clear user disclosure or consent, while processing potentially sensitive receipt images. In this context, undisclosed remote access is especially risky because receipts often contain personal and financial data, and the hardcoded account could silently exfiltrate, enumerate, or modify files on the remote Nextcloud instance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.