Back to skill

Security audit

founder-ledger

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward local income-ledger skill that writes a user-selected JSON file and does not show hidden execution, exfiltration, or persistence beyond that ledger file.

Install only if you are comfortable keeping revenue entries in a local plaintext JSON file. Use --file for test ledgers, keep real ledgers in a private directory, and remember that undo removes the latest entry but does not erase already recorded milestones.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
founder_ledger.py:143
Finding

Ledger Files May Be Created with Overly Broad Permissions

Content
View full analysis

Vulnerability Details

File Location: founder_ledger.py:143-144
Vulnerability Type: Insecure file permissions exposing plaintext financial data
Risk Level: Low

python
def save(path: Path, ledger: Ledger) -> None:
    path.write_text(json.dumps(ledger.to_json(), indent=2) + "\n")

Technical Analysis

The application stores ledger amounts, dates, descriptions, and revenue sources in plaintext JSON. When the destination does not already exist, Path.write_text() creates it using permissions derived from the process umask rather than explicitly enforcing owner-only access.

With a common 022 umask, a newly created ledger can receive mode 0644, making it readable by other local users. The code does not subsequently restrict the file to mode 0600. Exploitation requires another account on the same system to have traversal access to the ledger's parent directories and read access granted by the resulting mode.

Attack Path

  1. A user runs an operation that saves a new ledger, such as python3 founder_ledger.py add 5 "Customer payment".
  2. save() creates ledger.json through Path.write_text().
  3. The operating system applies the current process umask. Under a typical 022 umask, the resulting file may be mode 0644.
  4. Another local user who can traverse the parent directory opens the ledger file.
  5. That user reads the victim's amounts, transaction dates, descriptions, revenue sources, and milestone history.

Impact Assessment

This flaw can cause local confidentiality loss for the selected ledger file. An attacker may obtain sensitive business and financial records but does not gain code execution, elevated privileges, or remote access through this issue alone. The practical scope depends on the host's user model, umask, directory permissions, and any pre-existing permissions on the destination file.

Remediation
View remediation

Remediation Suggestions

  • Create new ledger files with explicit owner-only permissions, such as mode 0600, instead of relying on the process umask.
  • Write updates to a same-directory temporary file created securely with tempfile.mkstemp() or an equivalent exclusive-create operation.
  • Apply mode 0600 to the temporary file, flush buffered data, and call os.fsync() before atomically replacing the destination with os.replace().
  • Consider rejecting symbolic-link destinations where the application should only operate on regular files.
  • Verify and, where appropriate, tighten permissions on existing ledger files before writing.
  • Document that ledger contents are plaintext and should be stored in a private directory protected by restrictive permissions.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation declares no explicit tool scope even though the skill clearly relies on environment-variable access and local file read/write behavior. This weakens least-privilege guarantees and can cause an agent platform or user to authorize the skill without a clear understanding that it can read from an env-controlled path and persistently modify local data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown does not prominently warn users that commands mutate local ledger data and that milestone records are intentionally irreversible even after undo. This can mislead users into running destructive or non-reversible operations under the assumption that undo fully restores prior state, causing integrity and audit-history surprises.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.