Back to skill

Security audit

Financial Calculator Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent financial calculator, but it needs Review because its web UI is under-scoped for a local tool and depends on mutable third-party code.

Install only if you are comfortable reviewing or mitigating the web UI risks. Prefer changing the server to bind to 127.0.0.1, adding input limits, pinning Python dependencies, and vendoring or integrity-pinning Chart.js before using it with sensitive financial data or on a shared network.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/web_ui.py:137
Finding

Unauthenticated Network Exposure Enables Resource-Exhaustion Attacks

Content
View full analysis
1 else principal interest = balance - prev_balance total_interest += interest timeline.append({ 'year': year, 'balance': round(balance, 2), 'interest': round(interest, 2), 'total_interest': round(total_interest, 2) }) return jsonify({'success': True, 'timeline': timeline}) except Exception as e: return jsonify({'success': False, 'error': str(e)}), 400 @app.route('/api/multi-growth', methods=['POST']) def api_multi_growth(): """Generate multi-rate growth comparison""" data = request.json try: principal = float(data['principal']) rates = [float(r) / 100 for r in data['rates']] years = int(data['years']) frequency = int(data.get('frequency', 1)) series = [] for rate in rates: values = [] ...[truncated 3138 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/launch_ui.sh:11
Finding

Automatic Installation of Unpinned Python Dependencies

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
assets/calculator.html:7
Finding

Third-Party Browser Script Loaded Without Subresource Integrity

Content
View full analysis
``` ### Technical Analysis The calculator page executes Chart.js directly from the jsDelivr content delivery network. Although the URL specifies a package version, the script element does not provide a Subresource Integrity hash. The browser therefore verifies transport security through HTTPS but does not verify that the returned resource matches a project-reviewed byte sequence. Remote JavaScript executes with the privileges of the calculator page's browser origin. If the CDN response, package artifact, or delivery path were compromised, the returned script could interact with the page, read calculator inputs and results, modify displayed calculations, issue same-origin requests to the Flask API, and send information to remote servers. This is distinct from an intentionally malicious remote payload: the audited URL points to the legitimate Chart.js package. The security issue is the absence of integrity pinning and the resulting dependence on a third party at every page load. ### Attack Path 1. A user opens the calculator page. 2. The browser requests the Chart.js bundle from `cdn.jsdelivr.net`. 3. A compromise affecting the CDN, its package source, or the served artifact causes the request to return modified JavaScript. 4. Because no `integrity` attribute is present, the browser accepts and executes the modified response. 5. The script runs in the calculator page and can observe or manipulate financial inputs, outputs, DOM content, and same-origin API interactions. 6. The malicious script may transmit captured information to an attacker-controlled endpoint, subject to browser and network controls. ### Impact Assessment Successful exploitation would provide control ove ...[truncated 398 chars]
Remediation
View remediation
``` The hash must be calculated from or copied from a trusted source for the exact artifact; a placeholder must never be deployed. 3. Add a restrictive Content Security Policy that limits script sources to the local origin and, only if necessary, the explicitly approved CDN. 4. Pin the vendored or integrity-protected file to an exact reviewed version and update it only through a documented dependency-review process. 5. Consider using CSP nonces or external local JavaScript files instead of inline event handlers and inline scripts, enabling a stronger policy that avoids `unsafe-inline`. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code largely matches the declared financial-calculator purpose: it performs future value, present value, discount, markup, compound interest, and table generation, and includes a CLI. However, the description explicitly claims both a CLI and an interactive web UI, while this code chunk only shows the core engine plus CLI behavior. Additionally, the code contains annuity future value and annuity present value capabilities that are not mentioned in the description. These are related financial features rather than a different primary purpose, but they are still undeclared capabilities. No suspicious resource access, unrelated triggers, or non-financial behavior is present.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The page imports executable JavaScript from a third-party CDN, which creates a software supply-chain risk: if the CDN, package, or delivery path is compromised, arbitrary code would run in the skill UI. In a financial calculator context, that code could tamper with displayed calculations, exfiltrate user-entered financial data, or manipulate API requests, making the issue more sensitive than a purely decorative third-party asset.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The document sets the root language to English with lang="en", which establishes a fixed language/locale choice in the file's natural-language metadata. Under the stated policy, forcing a specific language without user opt-in can be a locale policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This HTML file contains JavaScript code that posts user-entered financial data to backend endpoints using fetch, but there is no visible warning, confirmation, or disclosure in the UI that these values will be transmitted off the page. Because the operations send user data over the network, they fall under missing user warnings for code files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.