Back to skill

Security audit

Family Account Book 家庭财务记账

Security checks for vulnerabilities and agentic risk

Overview

This household finance skill is not malicious, but it should be reviewed because it can persistently change local financial records from broad natural-language triggers without sufficient validation or confirmation.

Install only if you are comfortable letting the agent write to a local household finance SQLite database. Require explicit confirmation before any add, transfer, initialization, or account-affecting action, keep backups, prefer account IDs over fuzzy names, and avoid using it for authoritative financial records until amount validation, ledger scoping, and atomic transfer handling are added.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/finance_db.py:102
Finding

Unvalidated transaction fields permit financial record and balance manipulation

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/finance_db.py:201
Finding

Account resolution is not scoped to the requested ledger

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:61
Finding

Documented transfer workflow is non-atomic and can create one-sided transfers

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill description promises limited bookkeeping features, but the documented behavior includes local SQLite persistence, ad hoc Python database queries, and state-changing financial operations that are not fully disclosed or consistently implemented. In a financial skill, mismatches between declared scope and actual data-modifying behavior increase the risk of unintended writes, user surprise, and unsafe agent invocation on ambiguous requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is overly broad and overlaps with ordinary conversation about spending, salary, budgets, and balances, making accidental invocation plausible. Because this skill performs persistent financial writes and transfer-related actions, broad triggering materially raises the chance that casual language is interpreted as authorization to modify sensitive financial records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes add-entry and transfer workflows without clearly warning that these operations will persistently modify financial data. In the context of a household finance skill, missing write warnings and confirmation expectations can lead to silent or mistaken ledger changes, especially when combined with broad triggering and natural-language examples.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The '核心原则' section states '账户用ID(如B001),不是名称', which is an explicit instruction about intended behavior. However, the command examples throughout the file use names such as '主账户' and '日常支出' in the actual finance_db.py invocations, contradicting that documented intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file includes natural-language strings and docstrings in Chinese, and the CLI usage/help output is only presented in Chinese. That imposes a specific language on users without offering a language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.