Back to skill

Security audit

family-ledger 家庭记账skill

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real local family-ledger skill, but it has unsafe command-execution and deletion behavior that deserves review before installation.

Install only if you are comfortable reviewing or narrowing the execution rules first. The safest changes are to remove the broad Claude permissions, invoke ledger.py with structured arguments instead of shell-string templates, validate user-supplied fields, and require confirmation before deleting records.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:27
Finding

Shell Command Injection Through User-Controlled Ledger Arguments

Content
View full analysis
--amount --note "" ``` ### Technical Analysis The Skill instructs the agent to interpolate values parsed from natural-language user input directly into a shell command. The `role` value is not quoted at all, and the `note` value can escape its double-quoted context by including a quotation mark. No instruction requires shell-safe escaping, strict validation, or invocation through a structured argument-array API. The parameterized SQLite queries in `ledger.py` prevent SQL injection, but they do not prevent this vulnerability because shell parsing occurs before `ledger.py` receives the arguments. For example, a malicious role resembling the following could introduce an additional command: ```text father; python3 -c 'ATTACKER_CONTROLLED_PYTHON' # ``` When directly substituted into the documented template and executed through a shell, the resulting command would resemble: ```bash python3 /home/ubuntu/projects/record-family/ledger.py add --role father; python3 -c 'ATTACKER_CONTROLLED_PYTHON' # --amount 100 --note "groceries" ``` The shell would treat the semicolon as a command separator and execute the injected Python command independently. ### Attack Path 1. An attacker submits a natural-language ledger request containing shell metacharacters in the role or purpose. 2. The agent identifies the request as an expense-recording operation. 3. Following the Skill instructions, the agent inserts the attacker-controlled values into the documented command string. 4. The agent sends the constructed string to a shell execution tool. 5. The shell interp ...[truncated 957 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
.claude/settings.local.json:4
Finding

Overbroad Unattended Python Execution Permission

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · .claude/settings.local.json (reported line 5)May include surrounding context.

json
"permissions": {
    "allow": [
      "Bash(python3 *)",
      "Bash(curl -s \"https://api.github.com/search/code?q=skill+extension:md+repo:NousResearch/hermes-agent&per_page=5\")",
      "WebFetch(domain:hermes-agent.nousresearch.com)",
      "WebFetch(domain:docs.openclaw.ai)",
      "Bash(curl -s \"https://raw.githubusercontent.com/farion1231/cc-switch/main/README.md\")",

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · .claude/settings.local.json (reported line 13)May include surrounding context.

json
"Bash(curl -s \"https://agentskills.io\")",
      "Bash(curl -s \"https://raw.githubusercontent.com/agentskills/agentskills/main/README.md\")",
      "Bash(mkdir -p /home/ubuntu/projects/record-family/.claude/commands)",
      "Bash(cp /home/ubuntu/projects/record-family/skills/family-ledger/SKILL.md /home/ubuntu/projects/record-family/.claude/commands/family-ledger.md)",
      "Bash(git add *)"
    ]
  }

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill description and all invocation examples are presented as Chinese natural-language commands, implying a language-specific interaction model. There is no statement that the skill is Chinese-only by design, nor any opt-in or alternative language guidance, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports a destructive delete --id <ID> operation and instructs the agent to 'directly execute commands and return results' without any warning, confirmation, or preview. In an agent setting, ambiguous parsing, user typos, or prompt injection through user input could cause irreversible record deletion, making this materially unsafe even though the underlying action is limited to ledger entries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description limits the skill to '记录和查询家庭支出' (record and query family expenses). While recording and querying are implemented elsewhere, this command also removes existing data, which is a broader destructive capability not reflected in the stated description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The delete operation permanently removes records immediately based only on an ID, with no confirmation prompt, soft-delete, or undo capability. In a ledger context, accidental or induced invocation can cause integrity loss of financial records, especially because CLI tools may be called by higher-level agents or scripts where unintended destructive actions are harder to notice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The query intent matching is defined with very broad trigger words such as “查看/记录/列表/最近”, which can overlap with ordinary conversation and cause unintended command execution. In a skill that directly executes CLI actions, ambiguous matching increases the chance of exposing ledger data or running the wrong operation without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill supports a destructive delete command and instructs the agent to execute commands directly, but it does not require confirmation, preview, or safety checks before deletion. This creates a real risk of accidental or socially engineered data loss, especially because natural-language parsing may misinterpret user input and immediately remove records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown explicitly advertises a deletion capability with the example "删除第3条", but it does not warn users that this removes stored ledger data. For markdown files, destructive behaviors that can affect user data should be accompanied by a warning or disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill metadata and instructions are entirely in Chinese and present the assistant role in Chinese without indicating that the user can choose another language. This can violate language/locale policy when no opt-in or documented locale constraint is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description, help text, and all user-facing output strings are written only in Chinese, with no option for the user to choose another language or indication that the tool is intentionally limited to a Chinese-speaking context. This creates a language/locale policy issue because the skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

L03 以及全文说明均以中文固定描述技能行为,未表明这是区域/用户群限定工具,也未提供语言选择或按用户偏好响应的选项。根据语言/地区政策,强制单一语言而无用户选择可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.