Back to skill

Security audit

Monarch Money

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-built for Monarch Money, but it handles highly sensitive financial credentials and long-lived sessions with weak local safeguards.

Review before installing. Use only on a trusted personal machine, avoid shared or recorded terminals, consider fixing the password prompt and session-file permissions first, and delete ~/.monarchmoney/mm_session.pickle when you no longer want local access retained.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Security-Sensitive Third-Party Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/login_setup.py:38
Finding

Monarch Money Password Is Entered Through an Echoing Terminal Prompt

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/login_setup.py:64
Finding

Long-Lived Financial Session Is Saved Without Explicit Permission Hardening

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to authenticate interactively and states that a session is saved to '~/.monarchmoney/mm_session.pickle' for months, but it does not prominently warn about the persistence and sensitivity of that local credential material. If the host is shared, compromised, or insufficiently permissioned, the stored session could allow unauthorized access to detailed financial data without re-entering credentials or MFA.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger language is extremely broad, including 'any personal finance query,' which can cause the skill to activate in many contexts beyond explicit user intent. Because this skill accesses sensitive financial data and can trigger account refresh actions, over-invocation increases the risk of unnecessary exposure of private information or accidental execution of state-changing operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script persists an authenticated Monarch Money session to a predictable file in the user's home directory, and while it mentions that sessions persist for months, it does not clearly warn that the file is a sensitive credential equivalent that can grant access to financial data if copied by another local process or user. In a finance skill, this is more sensitive than usual because the stored session can expose account balances, transactions, budgets, and linked financial account access without requiring the password again.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The code relies on a persisted session file in the user's home directory and loads it directly for authenticated access to Monarch Money. If that session file is readable by other local users, copied from backups, or exposed through another process, an attacker could reuse it to access financial data without re-authentication.

Content

Scanner excerpt · scripts/monarch.py (reported line 34)May include surrounding context.

python
async def get_authenticated_client() -> MonarchMoney:
    """Load saved session and return authenticated client."""
    if not SESSION_FILE.exists():
        raise RuntimeError(
            f"Not authenticated. Run login_setup.py first. "

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script retrieves highly sensitive financial information such as account balances, transactions, budgets, and cashflow, then unconditionally prints the full results to stdout. In agent or multi-tool environments, stdout is often captured in logs, surfaced to other components, or retained in transcripts, which can expose private financial data beyond the intended recipient.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.