Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Copilot Money Mac

Query and analyze personal finance data from the Copilot Money Mac app. Use when the user asks about their spending, transactions, account balances, budgets,...

MIT-0 · Free to use, modify, and redistribute. No attribution required.
0 · 461 · 0 current installs · 0 all-time installs
byCharlie DiGiovanna@chardigio
MIT-0
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description match the runtime instructions: the SKILL.md explicitly targets the Copilot Money SQLite DB and Firestore LevelDB cache in macOS app containers and provides SQL and shell commands to read that data. The requested access (local DB files) is proportional to the stated functionality.
Instruction Scope
Instructions tell the agent to read sensitive local files (~/Library/Group Containers/... and ~/Library/Containers/...), use sqlite3 and strings to extract data, and run SQL queries. This is necessary for the task, but the skill contains no guidance on limiting or redacting sensitive output and assumes queries are read-only; users should treat any execution that reads financial data as highly sensitive.
Install Mechanism
Instruction-only skill with no install spec or external downloads. Nothing is written to disk by the skill itself and no third-party packages are pulled in.
Credentials
The skill requests no environment variables, credentials, or config paths beyond the local app data paths it documents. Those paths are directly relevant to the stated purpose.
Persistence & Privilege
always: false and no special privileges requested. The skill does not request permanent presence or attempt to modify other skills or system-wide settings. Autonomous invocation is allowed by platform default but is not granted here with any extra privileges.
Assessment
This skill is coherent: it documents where Copilot Money stores local data and how to query it with sqlite3 and strings. However, the files it reads contain highly sensitive personal financial information. Before installing or using it: 1) Only install if you trust the skill source (this package has no homepage and an unknown owner). 2) Prefer user-invoked use (don’t permit unattended/autonomous runs), and review any queries before they run. 3) Be aware the SKILL.md assumes read-only access but doesn't enforce it—avoid running write/update SQL. 4) If you’re uncomfortable giving an agent automated access to local finance files, run the shown sqlite3/strings commands yourself in a terminal instead of granting agent access. 5) Verify the Copilot Money app paths match your system and back up the DB before experimenting. If you want stronger assurance, request a signed/published skill from a known publisher or ask the maintainer to include explicit data-handling and privacy constraints.

Like a lobster shell, security has layers — review code before you run it.

Current versionv1.0.0
Download zip
latestvk975p20n6dek9s5m26ncse705581atfs

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

SKILL.md

Copilot Money

Query local data from the Copilot Money Mac app to analyze transactions, spending patterns, account balances, investments, and budgets. Data is stored in both SQLite (transactions, balances) and Firestore LevelDB cache (recurring names, budgets, investments).

Database Location

~/Library/Group Containers/group.com.copilot.production/database/CopilotDB.sqlite

Schema

Transactions Table

Primary table for all financial transactions.

ColumnTypeDescription
idTEXTPrimary key
dateDATETransaction date
nameTEXTMerchant/transaction name
original_nameTEXTRaw name from bank
amountDOUBLETransaction amount (positive = expense)
iso_currency_codeTEXTCurrency (e.g., "USD")
account_idTEXTLinked account reference
category_idTEXTCategory reference
pendingBOOLEANWhether transaction is pending
recurringBOOLEANWhether transaction is recurring
recurring_idTEXTLinks to recurring definition (see Firestore)
user_noteTEXTUser-added notes
user_deletedBOOLEANSoft-deleted by user

accountDailyBalance Table

Daily balance snapshots per account.

ColumnTypeDescription
dateTEXTSnapshot date
account_idTEXTAccount reference
current_balanceDOUBLEBalance on that date
available_balanceDOUBLEAvailable balance

Firestore Cache (LevelDB)

Additional data is stored in Firestore's local LevelDB cache, not in the SQLite database.

Location:

~/Library/Containers/com.copilot.production/Data/Library/Application Support/firestore/__FIRAPP_DEFAULT/copilot-production-22904/main/*.ldb

Collections

CollectionDescription
itemsLinked bank accounts/institutions
investment_pricesHistorical security prices
investment_performanceTWR (time-weighted return) per holding
investment_splitsStock split history
securitiesStock/fund metadata
users/.../budgetsBudget definitions (amount, category_id)
users/.../recurringsRecurring transaction definitions
amazonAmazon order matching data

Recurring Definitions

FieldDescription
nameDisplay name (e.g., "Water / Sewer", "Rent")
match_stringTransaction name to match (e.g., "CHECK PAID")
plaid_category_idCategory ID for the recurring
state"active" or "inactive"

Data Not in SQLite

  • Recurring names - human-readable names like "Rent", "Netflix"
  • Budget amounts - monthly budget per category
  • Investment data - holdings, prices, performance, splits
  • Account/institution names - Chase, Fidelity, etc.
  • Category names - Restaurants, Travel, Groceries, etc.

Extracting Data from LevelDB

List all recurring names:

for f in ~/Library/Containers/com.copilot.production/Data/Library/Application\ Support/firestore/__FIRAPP_DEFAULT/copilot-production-22904/main/*.ldb; do
  strings "$f" 2>/dev/null | grep -B10 "^state$" | grep -A1 "^name$" | grep -v "^name$" | grep -v "^--$"
done | sort -u | grep -v "^$"

List all collections:

for f in ~/Library/Containers/com.copilot.production/Data/Library/Application\ Support/firestore/__FIRAPP_DEFAULT/copilot-production-22904/main/*.ldb; do
  strings "$f" 2>/dev/null
done | grep -oE "documents/[a-z_]+/" | sort | uniq -c | sort -rn

Find category names:

for f in ~/Library/Containers/com.copilot.production/Data/Library/Application\ Support/firestore/__FIRAPP_DEFAULT/copilot-production-22904/main/*.ldb; do
  strings "$f" 2>/dev/null
done | grep -iE "^(groceries|restaurants|shopping|entertainment|travel|transportation|utilities)$" | sort -u

Common Queries

Recent Transactions

SELECT date, name, amount, category_id
FROM Transactions
WHERE user_deleted = 0
ORDER BY date DESC
LIMIT 20;

Monthly Spending Summary

SELECT strftime('%Y-%m', date) as month, SUM(amount) as total
FROM Transactions
WHERE amount > 0 AND user_deleted = 0
GROUP BY month
ORDER BY month DESC;

Spending by Category

SELECT category_id, SUM(amount) as total, COUNT(*) as count
FROM Transactions
WHERE amount > 0 AND user_deleted = 0 AND date >= date('now', '-30 days')
GROUP BY category_id
ORDER BY total DESC;

Search Transactions

SELECT date, name, amount
FROM Transactions
WHERE name LIKE '%SEARCH_TERM%' AND user_deleted = 0
ORDER BY date DESC;

List Recurring Transactions

SELECT DISTINCT name, recurring_id
FROM Transactions
WHERE recurring = 1 AND user_deleted = 0
ORDER BY name;

Usage

Use sqlite3 to query the database:

sqlite3 ~/Library/Group\ Containers/group.com.copilot.production/database/CopilotDB.sqlite "YOUR_QUERY"

For formatted output:

sqlite3 -header -column ~/Library/Group\ Containers/group.com.copilot.production/database/CopilotDB.sqlite "YOUR_QUERY"

Notes

  • Category IDs are opaque strings - group by them for analysis (names are in Firestore cache)
  • Amounts are positive for expenses, negative for income
  • Filter user_deleted = 0 to exclude deleted transactions
  • Both databases are actively used by the app; read-only access is safe
  • SQLite has recurring_id linking to Firestore recurring definitions
  • Use strings on LevelDB files to extract human-readable data from Firestore cache

Files

2 total
Select a file
Select a file to preview.

Comments

Loading comments…