Back to skill

Security audit

Invoice Generator

Security checks for vulnerabilities and agentic risk

Overview

This invoice PDF skill appears purpose-aligned, but it directly uses a vulnerable templating dependency in the core invoice-rendering path.

Review before installing. The behavior is not deceptive, but the Handlebars dependency should be upgraded or otherwise verified before using this with real customer, tax, or billing data. Also note the package appears to reference artifact/assets/invoice.hbs, but that template file was not present in the inspected artifact, so generation may fail unless supplied elsewhere.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Known Vulnerable Dependency: handlebars==4.7.8 — 8 advisory(ies): CVE-2026-33916 (Handlebars.js has Prototype Pollution Leading to XSS through Partial Template In); CVE-2026-33937 (Handlebars.js has JavaScript Injection via AST Type Confusion); CVE-2026-33938 (Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @part) +5 more

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

The lockfile pins handlebars 4.7.8, and the finding indicates multiple known critical advisories affecting that version, including prototype pollution and template/AST-driven code or script injection paths. In an invoice-generation skill, templating libraries often process user-supplied invoice data and possibly templates, so exploitation could lead to XSS in rendered HTML/PDF workflows, data tampering, or code execution within the templating context depending on how the library is used.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: handlebars==4.7.8 — 8 advisory(ies): CVE-2026-33916 (Handlebars.js has Prototype Pollution Leading to XSS through Partial Template In); CVE-2026-33937 (Handlebars.js has JavaScript Injection via AST Type Confusion); CVE-2026-33938 (Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @part) +5 more

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

This skill depends on Handlebars 4.7.8, which is flagged as having multiple known critical vulnerabilities including prototype pollution and possible XSS/JavaScript injection paths. In an invoice-generation skill, templating is central functionality and may process user-supplied invoice fields, making vulnerable template handling especially dangerous if untrusted data or templates can influence rendering.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is specified with a caret range (^4.7.8), which allows installation of different patch/minor versions over time and reduces build reproducibility. While unpinned versions are primarily a supply-chain hygiene issue rather than an immediate exploit by themselves, they can cause unexpected or unsafe dependency changes if a compromised or breaking upstream release is pulled.

Content

Scanner excerpt · package.json (reported line 6)May include surrounding context.

json
"version": "1.0.0",
  "private": true,
  "dependencies": {
    "handlebars": "^4.7.8"
  }
}

Static analysis

No suspicious patterns detected.