Back to skill

Security audit

Auto Accounting

Security checks for vulnerabilities and agentic risk

Overview

This bookkeeping skill has a coherent purpose, but it handles sensitive financial screenshots and can automate account-record changes without enough user confirmation or containment.

Review this before installing if you care about financial-data privacy or bookkeeping accuracy. Enable confirmation before saving records, use only trusted versions of the image and GUI dependencies, keep any local history in a private directory, and verify that automation cannot leave the intended accounting app.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
scripts/accounting_parser.py:341
Finding

Untrusted OCR Output Is Interpolated into a GUI-Agent Instruction

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/user_preferences.py:32
Finding

Accounting Entries Can Be Saved Without User Confirmation by Default

Content
View full analysis
bool: """ Determine whether confirmation is required before saving. """ if self.get("confirm_before_save", False): return True threshold = self.get("large_amount_threshold", 1000) return amount >= threshold ``` The intended behavior is explicitly verified in `tests/test_accounting.py:178-181`: ```python def test_confirm_threshold(self): assert self.prefs.should_confirm_before_save(500) == False assert self.prefs.should_confirm_before_save(1500) == True ``` ### Technical Analysis The default configuration permits records below the large-amount threshold to proceed without explicit user confirmation. This is unsafe because transaction recognition relies on broad OCR heuristics and model-produced data. The parser considers text containing common terms such as payment, order, amount, currency symbols, or receipts to be accounting-related. Such terms can occur in advertisements, historical screenshots, demonstrations, refund notices, or deliberately crafted images. Therefore, the system cannot safely assume that every recognized transaction represents a user's intent to create a new record. The issue is an integrity failure rather than direct privilege escalation: uncertain machine interpretation is allowed to trigger a financial state-changing action without an affirmative user decision. ### Attac ...[truncated 885 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/accounting_history.py:53
Finding

Financial History and Failure Records Are Stored as Unprotected Plaintext Files

Content
View full analysis
bool: """Save accounting history.""" if not self.history_path: return False try: os.makedirs(os.path.dirname(self.history_path), exist_ok=True) with open(self.history_path, 'w', encoding='utf-8') as f: json.dump(self.history, f, ensure_ascii=False, indent=2) return True except IOError: return False ``` The same pattern is used for failed records at `scripts/accounting_history.py:232-243`: ```python def save_failed(self) -> bool: """Save failed records.""" if not self.failed_path: return False try: os.makedirs(os.path.dirname(self.failed_path), exist_ok=True) with open(self.failed_path, 'w', encoding='utf-8') as f: json.dump(self.failed_records, f, ensure_ascii=False, indent=2) return True except IOError: return False ``` Preference data is written similarly at `scripts/user_preferences.py:65-76`: ```python def save_preferences(self) -> bool: """Save preferences.""" if not self.preferences_path: return False try: os.makedirs(os.path.dirname(self.preferences_path), exist_ok=True) with open(self.preferences_path, 'w', encoding='utf-8') as f: json.dump(self.preferences, f, ensure_ascii=False, indent=2) return True except IOError: return False ``` ### Technical Analysis Accounting and failure records are serialized directly to caller-selected paths as plaintext JSON. No restrictive file mode is explicitly applied, so confidentiality depends on the process umask and properties of the selected directory. The implementation does not constrain paths to an application-private storage root. A caller can therefore selec ...[truncated 1567 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:16
Finding

Security-Sensitive Automation Dependencies Use Floating Version Constraints

Content
View full analysis
=1.0.0", "xiaoyi-gui-agent": ">=1.0.0", "requests": "^2.31.0" } ``` Equivalent open-ended constraints also appear in `_meta.json:9-21`: ```json "dependencies": [ { "name": "xiaoyi-image-understanding", "version": ">=1.0.0", "required": true }, { "name": "xiaoyi-gui-agent", "version": ">=1.0.0", "required": true } ] ``` ### Technical Analysis The two most security-sensitive dependencies are accepted at any version greater than or equal to `1.0.0`. There is no lockfile, package integrity hash, or reviewed upper bound in the audited project. These components occupy privileged trust positions: one processes private financial screenshots and the other controls phone UI interactions. A compromised, malicious, or incompatible future release could therefore receive highly sensitive input or exercise GUI authority without any change to the reviewed Skill package. The `requests` dependency is declared but not used by the executable project files. Unnecessary dependencies expand the supply-chain attack surface without providing functionality. The audit did not confirm that any currently resolved dependency is malicious. The vulnerability is the unsafe resolution policy and absent integrity controls. ### Attack Path 1. The Skill is installed or updated in an environment that resolves dependencies dynamically. 2. The package resolver selects a newer version satisfying the open-ended constraint. 3. The selected release is compromised, malicious, dependency-confused, or behaviorally incompatible. 4. The image component receives transaction screenshots, or the GUI component receives phone-control commands. 5. Malicious dependency code abuses its process privileges, image access, network ...[truncated 510 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
scripts/runtime_validator.py:86
Finding

Runtime and Target-Application Validation Can Be Trivially Spoofed or Bypassed

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding indicates runtime fingerprinting, app/package inspection, keyword inspection for competitor detection, and execution blocking outside approved environments. In context, the extensive anti-modification and anti-competition language increases suspicion that the skill may perform unauthorized environment surveillance and restrictive behavior beyond legitimate bookkeeping, which is dangerous when paired with access to screenshots and GUI automation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates runtime fingerprinting, app/package inspection, keyword inspection for competitor detection, and execution blocking outside approved environments. In context, the extensive anti-modification and anti-competition language increases suspicion that the skill may perform unauthorized environment surveillance and restrictive behavior beyond legitimate bookkeeping, which is dangerous when paired with access to screenshots and GUI automation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates runtime fingerprinting, app/package inspection, keyword inspection for competitor detection, and execution blocking outside approved environments. In context, the extensive anti-modification and anti-competition language increases suspicion that the skill may perform unauthorized environment surveillance and restrictive behavior beyond legitimate bookkeeping, which is dangerous when paired with access to screenshots and GUI automation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The validator hard-blocks execution outside a single vendor/runtime and a narrow app allowlist while the skill metadata claims support for multiple mainstream platforms. This creates a deceptive capability gap that can mislead users and platform operators, and it can be used as a hidden lock-in or anti-competitive control that only becomes apparent at runtime.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The example code performs an external POST request to an image-understanding API, which indicates data leaves the local environment. In the context of an auto-accounting skill that may handle receipts, payment screenshots, and transaction records, such transmission can expose sensitive financial and personal data if not explicitly controlled and disclosed.

Content

Scanner excerpt · CODE_PROTECTION.md (reported line 126)May include surrounding context.

md
signature = generate_signature(API_KEY, timestamp)
    
    # API 会验证签名,非授权调用会被拒绝
    response = requests.post(
        "https://xiaoyi.api/understanding",
        headers={
            "X-Timestamp": str(timestamp),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document proposes sending user images to a server-side API for image understanding, but it does not mention any user consent, privacy notice, data minimization, retention policy, or transport/security controls. Because this skill processes accounting screenshots that may contain financial and personal information, undocumented external transmission materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly promotes automatic extraction of transaction details from screenshots and automatic entry into an accounting app, but it provides no warning about handling sensitive financial and personal data. This creates a real privacy and integrity risk because users may upload receipts, order pages, and payment screenshots containing names, account details, addresses, and purchase history without informed consent or guidance on safe handling.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares no explicit tool scope or permissions, yet the documented file structure and static analysis indicate environment access plus local file read/write behavior. In an automation skill that processes financial screenshots and may persist history, missing scope declarations reduce transparency and prevent users or platforms from understanding what data the skill can access or store.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatic activation on any received image is insufficiently constrained for a skill that handles privacy-sensitive financial screenshots and can drive a GUI agent. This can lead to unintended processing of unrelated images, accidental extraction of sensitive data, or unintended writes into the bookkeeping app without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are generic terms like '记账', '账单', '消费', '支出', and '收入', which can appear in ordinary conversation. Broad triggers increase the chance of unintended activation, causing the skill to process screenshots or initiate bookkeeping actions when the user did not explicitly intend automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill processes screenshots containing financial and personal transaction details, but the description does not provide a clear privacy warning about extraction, storage, transmission, or retention of that data. Because this is finance-related and may involve local persistence plus GUI automation, the absence of a privacy notice materially increases the risk of uninformed consent and mishandling of sensitive data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manual trigger examples remain broad and do not define clear boundaries for what images or conversations should be processed. In a skill with image parsing and GUI automation, ambiguous commands can cause overcollection of financial information or accidental automated actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly states that the skill will automatically recognize accounting information from images and record it into a bookkeeping app, but it does not disclose how sensitive financial data is handled, stored, or confirmed before submission. Because this skill operates on payment and purchase screenshots, missing user warnings and consent boundaries increase the risk of privacy exposure, mis-entry, and unintended side effects in a finance context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger keywords are very broad everyday finance terms such as '记账', '账单', '消费', and '支出', which can cause the skill to activate in contexts where the user did not intend to launch an automation that processes images and records financial data. In a finance automation skill, unintended activation is more dangerous because it can lead to accidental extraction of sensitive payment information and unintended bookkeeping actions in another app.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The configuration disables confirmation before saving accounting entries by default, which can cause the agent to persist incorrect or hallucinated OCR/LLM-extracted financial data without user review. In this skill's context, the model is parsing screenshots from payment and shopping platforms, so extraction mistakes can directly create false bookkeeping records and privacy-sensitive financial actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest explicitly describes automated extraction of financial information from user images and automatic entry into a bookkeeping app, but it provides no notice about handling sensitive financial data, no consent model, and no warning about mistaken OCR-driven actions. In this context, the skill processes receipts/payment screenshots from platforms like WeChat and Alipay, so silent automation materially increases privacy and integrity risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The clear_history method erases all in-memory accounting history and immediately writes the empty state to disk via save_history, making the action effectively destructive. There is no confirmation prompt, visible warning, or explicit disclosure in this file that all stored records will be permanently cleared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring and surrounding user-facing text are entirely in Chinese and tied to a specific app/environment, with no indication that language selection is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code explicitly checks the target app package and raises a PermissionError when it detects competing accounting apps, enforcing undisclosed vendor exclusivity at runtime. This is a genuine security/integrity issue because the skill behavior diverges from its general-purpose description and can be used to restrict user autonomy or sabotage interoperability in multi-app environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header text states that the skill may only be used in an 'official' environment and a specific app, without giving users choice or technical justification. While not directly exploitable like code execution, this is a concerning policy signal because it indicates intentional restriction beyond the declared accounting function and increases suspicion when combined with runtime enforcement elsewhere in the file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file enforces use of an 'authorized' runtime and app, and exits when those conditions are not met, but the user-facing description does not disclose these restrictions. Hidden platform enforcement is risky because it changes the trust model of the skill, can coerce users into a specific ecosystem, and may conceal nonfunctional policy controls inside operational code.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The validator checks for platform-identifying environment variables and refuses to run outside a vendor-specific environment, even though the stated skill purpose is image-based accounting automation. This creates an unnecessary execution gate that can mislead users, reduce portability, and impose undisclosed platform lock-in unrelated to core functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language docstrings and user-facing messages entirely in Chinese, including the skill title and runtime restrictions, with no indication that users can opt into another language. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header claims MIT-0 licensing but then adds usage restrictions that MIT-0 does not permit, creating a contradictory and potentially deceptive licensing posture. This can expose users and integrators to legal ambiguity and can be used to pressure or block legitimate analysis, redistribution, or deployment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code enforces a vendor-specific runtime requirement through environment-based checks that are not disclosed in the manifest description. Hidden execution constraints are risky because they undermine informed consent, portability, and trust, especially for an automation skill expected to run across multiple platforms.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.