Back to skill

Security audit

Manage YNAB budgets, accounts, categories, and transactions.

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent YNAB helper, but it gives an agent live financial-data write and delete capabilities without safety guidance or scoped controls.

Review this skill before installing. Use it only if you are comfortable giving the agent a YNAB API key and the ability to change or delete live budget data. Prefer pinning and reviewing the npm package version, avoid elevated installs, and require explicit confirmation before any create, update, delete, split, budget, payee, or raw API POST command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 4 and 9–11
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Complete Code Snippet:

yaml
metadata: {"clawdbot":{"emoji":"💰","requires":{"bins":["ynab"],"env":["YNAB_API_KEY"]},"primaryEnv":"YNAB_API_KEY","install":[{"id":"node","kind":"node","package":"@stephendolan/ynab-cli","bins":["ynab"],"label":"Install ynab-cli (npm)"}]}}
bash
npm i -g @stephendolan/ynab-cli

Technical Analysis

The Skill directs users and the hosting framework to install @stephendolan/ynab-cli without specifying a reviewed version or package integrity value. Consequently, installation resolves whichever release is current in the npm registry at installation time. The -g option installs the package globally, expanding its reach beyond the project directory.

npm packages can execute lifecycle scripts during installation. If the package, a transitive dependency, the publisher account, or the upstream release process is compromised, attacker-controlled code could execute with the permissions of the user performing the installation. The installed CLI subsequently operates in an environment containing YNAB_API_KEY, so a compromised dependency could access that credential when invoked.

This is a supply-chain exposure rather than evidence that the currently published package is malicious.

Attack Path

  1. An attacker compromises the npm package publisher, release pipeline, package contents, or a transitive dependency.
  2. The attacker publishes a malicious release under the existing package name.
  3. A user or agent follows the documented command or automated installation metadata.
  4. Because no version or integrity value is pinned, npm retrieves the malicious current release.
  5. Malicious lifecycle code may execute during global installation with the installer's permissions.
  6. The globally installed ynab exe ...[truncated 949 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specific version that has been reviewed, for example @stephendolan/ynab-cli@<reviewed-version>, in both the installation metadata and documentation.
  2. Record and verify package integrity using a lockfile or an equivalent cryptographic integrity mechanism.
  3. Prefer a project-local installation over npm i -g to reduce system-wide impact and make dependency resolution reproducible.
  4. Review the selected package version, its lifecycle scripts, and its transitive dependency tree before approval.
  5. Disable npm lifecycle scripts during installation when they are not required, such as with --ignore-scripts, after confirming that the CLI remains functional.
  6. Install and execute the CLI as an unprivileged user. Do not use elevated privileges for global npm installation.
  7. Limit exposure of YNAB_API_KEY to the process that requires it, rotate the token if compromise is suspected, and avoid persisting it in shell history or plaintext configuration.
  8. Establish an update process that reviews and tests each new version before changing the pinned dependency.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation exposes multiple state-changing and destructive commands such as transaction creation, update, deletion, scheduled deletion, category budgeting, payee updates, and raw API POST operations without any warning, confirmation guidance, or safe-usage constraints. In an agent-driven context, this increases the chance of accidental or unauthorized modification of a user's financial data, especially because the commands operate against a live YNAB account using an API key.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.