T09 · Insecure Skill Coding Practices
- Location
scripts/finance_db.py:102- Finding
Unvalidated transaction fields permit financial record and balance manipulation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This household finance skill is not malicious, but it should be reviewed because it can persistently change local financial records from broad natural-language triggers without sufficient validation or confirmation.
Install only if you are comfortable letting the agent write to a local household finance SQLite database. Require explicit confirmation before any add, transfer, initialization, or account-affecting action, keep backups, prefer account IDs over fuzzy names, and avoid using it for authoritative financial records until amount validation, ledger scoping, and atomic transfer handling are added.
scripts/finance_db.py:102Unvalidated transaction fields permit financial record and balance manipulation
scripts/finance_db.py:201Account resolution is not scoped to the requested ledger
SKILL.md:61Documented transfer workflow is non-atomic and can create one-sided transfers
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The skill description promises limited bookkeeping features, but the documented behavior includes local SQLite persistence, ad hoc Python database queries, and state-changing financial operations that are not fully disclosed or consistently implemented. In a financial skill, mismatches between declared scope and actual data-modifying behavior increase the risk of unintended writes, user surprise, and unsafe agent invocation on ambiguous requests.
The trigger description is overly broad and overlaps with ordinary conversation about spending, salary, budgets, and balances, making accidental invocation plausible. Because this skill performs persistent financial writes and transfer-related actions, broad triggering materially raises the chance that casual language is interpreted as authorization to modify sensitive financial records.
The documentation describes add-entry and transfer workflows without clearly warning that these operations will persistently modify financial data. In the context of a household finance skill, missing write warnings and confirmation expectations can lead to silent or mistaken ledger changes, especially when combined with broad triggering and natural-language examples.
The '核心原则' section states '账户用ID(如B001),不是名称', which is an explicit instruction about intended behavior. However, the command examples throughout the file use names such as '主账户' and '日常支出' in the actual finance_db.py invocations, contradicting that documented intent.
This code file includes natural-language strings and docstrings in Chinese, and the CLI usage/help output is only presented in Chinese. That imposes a specific language on users without offering a language choice or documenting a justified locale restriction.
No suspicious patterns detected.