Back to skill

Security audit

Monthly Financial Report

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently turns a user-provided fixed-format financial Excel workbook into local report files, with only disclosed and purpose-aligned risks.

Install in an isolated workspace when possible, verify the uploaded workbook and generated financial figures before use, and prefer pinned reviewed dependency versions for openpyxl and xlrd in production.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
SKILL.md:48
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 48 and 54
Vulnerability Type: Unpinned runtime dependencies
Risk Level: Low

Vulnerable Code

bash
pip install openpyxl
bash
pip install xlrd

Technical Analysis

The installation instructions retrieve openpyxl and xlrd from the configured Python package index without version constraints or package hash verification. Consequently, installations are not reproducible, and the code ultimately installed can change without any corresponding modification to this project.

The package names match the imports used by the report script, and the audit found no evidence of typosquatting, dependency confusion, an unsafe custom repository, or a currently malicious release. Nevertheless, resolving an unrestricted latest version creates supply-chain exposure: a compromised package publisher, package-index account, repository, or future upstream release could introduce malicious installation or runtime behavior.

Because Python packages can execute code during installation and when imported, compromise would occur with the privileges of the user or Agent environment running pip and the report script.

Attack Path

  1. A user asks the Agent to process a financial workbook.
  2. The Agent follows the first-use instructions in SKILL.md.
  3. It runs pip install openpyxl and, when legacy Excel support is needed, pip install xlrd.
  4. The package resolver selects the latest available versions from the environment's configured package index.
  5. If a selected distribution or its delivery channel has been compromised, attacker-controlled code executes during installation or when the report script imports the package.
  6. That code operates with the Agent process's filesystem, environment, and network permissions.

This path depends on an upstream package or package-delivery compromise; no such compromise was established during this audit.

Impact Assessment

Successful exploitatio ...[truncated 544 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency lock file containing exact versions rather than installing unconstrained latest releases.
  2. Record and enforce cryptographic hashes for every accepted distribution:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Example requirements entries should follow this model, using versions and hashes approved by the project:
    text
    openpyxl==<reviewed-version> \
        --hash=sha256:<reviewed-distribution-hash>
    xlrd==<reviewed-version> \
        --hash=sha256:<reviewed-distribution-hash>
    
  4. Install from a controlled package mirror or a prebuilt, security-reviewed runtime image where possible.
  5. Run dependency installation and workbook processing under a dedicated, least-privileged account in an isolated environment.
  6. Add automated vulnerability and provenance checks for dependency updates, and require review before changing pinned versions or hashes.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares executable commands that install packages, read environment state, write output files, and may construct download links from environment variables, but it does not declare an explicit tool/permission scope. That creates an authorization and review gap: an agent or platform may grant broader capabilities than users expect, increasing the risk of unintended file writes, package installation, or network-relevant behavior during execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is primarily written in Chinese and defines when to use the skill without offering any language or locale choice. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless clearly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s main instructions, workflow, response templates, and notes are presented in Chinese, which effectively constrains interaction to a single language. The file does not clearly justify this as a region-specific compliance or internal-only locale requirement, nor does it offer the user a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script hard-codes Chinese metric names, section names, date patterns, and output text, which means the generated report and expected input format are fixed to Chinese. There is no user opt-in, language selection, or explicit documentation in the file justifying this locale restriction as a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents the skill name and description in Chinese while the default prompt is fixed in English. This can impose a language choice implicitly rather than documenting or offering user opt-in for language/locale behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.