T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Security-Sensitive Third-Party Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is purpose-built for Monarch Money, but it handles highly sensitive financial credentials and long-lived sessions with weak local safeguards.
Review before installing. Use only on a trusted personal machine, avoid shared or recorded terminals, consider fixing the password prompt and session-file permissions first, and delete ~/.monarchmoney/mm_session.pickle when you no longer want local access retained.
SKILL.md:13Unpinned Security-Sensitive Third-Party Dependency
scripts/login_setup.py:38Monarch Money Password Is Entered Through an Echoing Terminal Prompt
scripts/login_setup.py:64Long-Lived Financial Session Is Saved Without Explicit Permission Hardening
The skill instructs users to authenticate interactively and states that a session is saved to '~/.monarchmoney/mm_session.pickle' for months, but it does not prominently warn about the persistence and sensitivity of that local credential material. If the host is shared, compromised, or insufficiently permissioned, the stored session could allow unauthorized access to detailed financial data without re-entering credentials or MFA.
The trigger language is extremely broad, including 'any personal finance query,' which can cause the skill to activate in many contexts beyond explicit user intent. Because this skill accesses sensitive financial data and can trigger account refresh actions, over-invocation increases the risk of unnecessary exposure of private information or accidental execution of state-changing operations.
The script persists an authenticated Monarch Money session to a predictable file in the user's home directory, and while it mentions that sessions persist for months, it does not clearly warn that the file is a sensitive credential equivalent that can grant access to financial data if copied by another local process or user. In a finance skill, this is more sensitive than usual because the stored session can expose account balances, transactions, budgets, and linked financial account access without requiring the password again.
The code relies on a persisted session file in the user's home directory and loads it directly for authenticated access to Monarch Money. If that session file is readable by other local users, copied from backups, or exposed through another process, an attacker could reuse it to access financial data without re-authentication.
async def get_authenticated_client() -> MonarchMoney:
"""Load saved session and return authenticated client."""
if not SESSION_FILE.exists():
raise RuntimeError(
f"Not authenticated. Run login_setup.py first. "
The script retrieves highly sensitive financial information such as account balances, transactions, budgets, and cashflow, then unconditionally prints the full results to stdout. In agent or multi-tool environments, stdout is often captured in logs, surfaced to other components, or retained in transcripts, which can expose private financial data beyond the intended recipient.
No suspicious patterns detected.