Back to skill

Security audit

AutoCount

Security checks for vulnerabilities and agentic risk

Overview

The skill matches AutoCount accounting automation, but it needs review because it documents API-key access over plain HTTP and includes live financial record mutation workflows.

Review before installing. Use this only against a trusted AutoCount environment protected by HTTPS, VPN, or another secure tunnel; prefer a dedicated least-privilege API key; test in drafts or a sandbox first; and require explicit confirmation before final posting, update, cancel, or delete operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:20
Finding

API credentials and sensitive accounting data transmitted over unencrypted HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20-40; corroborated by references/test-notes.md:3-19
Vulnerability Type: Cleartext transmission of authentication credentials and business data
Risk Level: High

Vulnerable Code Snippet

markdown
1. Confirm the base URL, API name, and API key.
2. Use the headers:
   - `X-API-NAME: 9999`
   - `X-API-KEY: 9999`
   - `Content-Type: application/json`
3. Prefer `SaveAsDraft: true` unless the user explicitly wants final posting.
4. For transfer chains, the source document must be final (`SaveAsDraft: false`). Draft purchase documents cannot be used as transfer sources.
5. Prefer AutoCount defaults (`<<<Default>>>`) over guessed business values.
6. Do not hardcode tax codes. Use defaults or system-derived values only.
7. After each create call, fetch the created record and report the actual document number.

## Known API pattern

Base URL example:
- `http://your-autocount-host:9999`

Headers example:
```http
X-API-NAME: <your-api-name>
X-API-KEY: <your-api-key>
Content-Type: application/json
text

The reference notes explicitly confirm the insecure transport:

```markdown
## Environment observed

- Base URL shape: `http://your-autocount-host:9999`
- Protocol in the tested environment: HTTP on 9999, not HTTPS
- Root path returned `404 Not Found`
- Server header observed in testing: `Microsoft-HTTPAPI/2.0`

## Auth behavior

- Basic auth failed
- `APIKey`, `ApiKey` headers did not work
- `X-API-KEY` triggered the next auth layer
- Missing companion header error showed `X-API-Name is required`
- Working auth shape:
  - `X-API-NAME: <your-api-name>`
  - `X-API-KEY: <your-api-key>`

Technical Analysis

The Skill instructs the Agent to authenticate to an AutoCount Web API using X-API-NAME and X-API-KEY headers while documenting an `http: ...[truncated 3508 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require https:// API endpoints and reject plain HTTP by default, especially for non-loopback hosts.
  2. If AutoCount does not support TLS directly, place it behind a properly configured TLS reverse proxy, VPN, or mutually authenticated secure tunnel.
  3. Validate TLS certificates and hostnames. Do not recommend disabling certificate verification.
  4. Replace the literal X-API-NAME: 9999 and X-API-KEY: 9999 examples with unambiguous placeholders.
  5. Obtain credentials from protected runtime secret storage or environment configuration rather than embedding them in Skill content, payload examples, logs, or generated commands.
  6. Redact authentication headers and sensitive accounting fields from logs, traces, error reports, and conversational output.
  7. Use dedicated, least-privilege API identities. Separate read-only inspection credentials from document-creation and destructive-operation credentials where the server supports it.
  8. Require explicit user confirmation immediately before update, cancellation, deletion, or final posting operations.
  9. Restrict server exposure with firewall allowlists and avoid exposing port 9999 directly to untrusted networks.
  10. Rotate any API credentials that have previously been transmitted over HTTP and review API or accounting logs for unauthorized access.
  11. Update references/test-notes.md to label the observed HTTP deployment as unsafe rather than presenting it as an acceptable operating configuration.
  12. Add a preflight check that refuses insecure transport and reports clear instructions for enabling TLS.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The notes explicitly describe a working authentication scheme using custom API headers over HTTP rather than HTTPS, which implies credentials may be transmitted in cleartext on the network. In a skill designed to automate access to a Windows-hosted accounting API, this makes credential interception and unauthorized API access materially more likely, especially on shared or corporate networks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

These notes document successful live creation of sales invoices, goods received notes, and purchase invoices, but do not warn operators to use a sandbox, drafts, or test companies only. In the context of an automation skill for business documents, that omission increases the chance of accidental writes to live accounting data, causing financial records pollution, reconciliation issues, and operational disruption.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.