Back to skill

Security audit

Organisation Documents

Security checks for vulnerabilities and agentic risk

Overview

This accounting skill is mostly coherent, but it asks to process sensitive financial documents automatically without authorization and writes long-lived local indexes and document copies.

Install only if you want an unattended French accounting-document organizer and can constrain it to a known inbox and client root. Before use, require an explicit opt-in for automatic email/file processing, review where PDFs and JSON indexes will be written, disable or document any external company lookup, and consider adding dry-run/audit/rollback controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This second mismatch finding also indicates that the declared accounting-ingestion workflow cannot be safely trusted as written. When a skill claims automatic inbox/document classification but instead validates JSON invoices or uses unrelated files and logic, users may unknowingly route sensitive documents into a component that does not perform the promised controls, producing both security and integrity failures.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This second mismatch finding also indicates that the declared accounting-ingestion workflow cannot be safely trusted as written. When a skill claims automatic inbox/document classification but instead validates JSON invoices or uses unrelated files and logic, users may unknowingly route sensitive documents into a component that does not perform the promised controls, producing both security and integrity failures.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates automatic invocation in many common situations and explicitly says to run without asking authorization, including on incoming email, attachments, file drops, and accounting keywords. In a finance context, such broad triggers can cause silent processing of untrusted content, automatic file movement, and shell-script execution on attacker-controlled documents, increasing the blast radius of phishing, prompt injection, or malformed-file attacks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly describes automatic moving/writing of accounting PDFs and JSON index files, including systematic invocation without asking authorization. In an agent context, silent filesystem mutation can cause unintended reorganization, overwrite-like logical corruption, or misfiling of sensitive accounting records if triggered on the wrong inbox or with ambiguous inputs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes behavior that clearly requires powerful capabilities such as shell execution and file read/write, yet it declares no explicit tool scope or permission boundaries. This creates an authorization gap where an agent may run with broader-than-expected privileges, making unintended filesystem changes or command execution harder to constrain and audit.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs automatic classification, renaming, and movement of accounting files without prominently warning users that files will be created or relocated as a side effect. In a bookkeeping environment, undisclosed modifications can break auditability, surprise operators, and make recovery harder if the skill misclassifies documents or processes malicious inputs automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The communication section prescribes a fixed vocabulary and all user-facing guidance is written exclusively in French, with no indication that the user can choose another language. This creates a locale policy issue because the skill appears to force a specific language without opt-in or an explicit documented justification for the restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly states that sender address, subject, date, and HTML body are ingested and used to infer client identity, but the reference provides no privacy guardrails, minimization rules, or user-facing disclosure. In this accounting context, email bodies and metadata can contain sensitive financial and personal data, so silent secondary use increases privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The roadmap explicitly lists capabilities to fetch email attachments, upload files to Drive, and read credentials, but does not mention any consent boundary, notice, or guardrails for handling sensitive financial documents and mailbox contents. In this skill’s context, the metadata even mandates automatic invocation without asking permission, which increases the risk of unauthorized access, privacy violations, and silent exfiltration of accounting data to external storage.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/structure-cible.md (reported line 86)May include surrounding context.

md
### Composants de nom de fichier

| Token            | Règle                                                                                                  |
| ---------------- | ------------------------------------------------------------------------------------------------------ |
| `AAAA-MM-JJ`     | `dateEmission` du document (ISO 8601), pas date de réception                                          |
| `AAAA-MM`        | `dateEmission` tronquée au mois — utilisé pour les relevés bancaires (couvre généralement un mois)    |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/structure-cible.md (reported line 238)May include surrounding context.

md
## Pourquoi cette structure

| Décision                                    | Alternative rejetée                          | Raison                                                                                  |
| ------------------------------------------- | -------------------------------------------- | --------------------------------------------------------------------------------------- |
| `<AAAA>/<MM>/` (deux niveaux)               | `<AAAA-MM>/` (un niveau)                     | Conservation 10 ans = 120 dossiers à plat ingérables sur Drive/Finder                   |
| `invoices/in` + `invoices/out` séparés      | `invoices/` unique                           | TVA et PCG différents — un compta ne mélange jamais                                     |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file contains natural-language instructions exclusively in French and does not state that French is optional, user-selected, or required for a clearly documented region-specific reason. Under the stated policy, forcing a specific language without opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/validation-fr.md (reported line 60)May include surrounding context.

md
Décision en cascade — première règle qui matche s'applique :

| Indice                                                                                                   | `categorie`      | Dossier cible              | Vocab comptable  |
| -------------------------------------------------------------------------------------------------------- | ---------------- | -------------------------- | ---------------- |
| Document de type relevé (mots-clés : « relevé », « extrait de compte », IBAN en en-tête sans n° facture) | `bank-statement` | `<AAAA>/<MM>/bank-statements/` | Relevés bancaires |
| Contrat (mots-clés : « contrat », « avenant », pas de montant TTC en clair)                              | `contrat`        | `contrats/` (racine client) | Contrats         |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/validation-fr.md (reported line 67)May include surrounding context.

md
| Émetteur = personne physique du cabinet ou d'un client                                                   | `note-de-frais`  | `<AAAA>/<MM>/notes-de-frais/` | Notes de frais   |
| `emetteur` ∈ clients du cabinet (le client a émis la facture à l'un de ses propres clients)              | `vente`          | `<AAAA>/<MM>/invoices/out/` | Ventes           |
| `emetteur` ∉ clients ET le client est destinataire                                                       | `achat`          | `<AAAA>/<MM>/invoices/in/`  | Achats           |
| Aucune correspondance                                                                                    | `autre`          | `<AAAA>/<MM>/autres/`       | Autres           |

**Ordre important** : `bank-statement` et `contrat` sont testés AVANT `vente`/`achat` car ils peuvent être émis par un client du cabinet sans être pour autant une vente (un relevé BNP avec émetteur = client ne doit pas atterrir dans `invoices/out/`).

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring contains usage and behavioral instructions exclusively in French, including normative guidance to the caller. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/extract.py (reported line 44)May include surrounding context.

python
def pdftext(path):
    try:
        r = subprocess.run(["pdftotext", "-layout", str(path), "-"],
                           capture_output=True, text=True, errors="ignore", timeout=30)
        return r.stdout
    except Exception:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says extraction and classification are done by scripts/main.py and scripts/extract.py and implies an automatic accounting-document pipeline, but this file introduces separate internet-based enrichment behavior. That mismatch is risky because the skill is configured to run automatically and systematically, so hidden external lookups can occur in contexts where users expect only local document handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This script sends user-provided company identifiers or names to a public government search API over the internet, creating outbound data flow beyond local document classification. In a comptable/document-processing skill, this can expose client-related business context or identifiers to third-party services and expands the trust boundary without being clearly disclosed in the skill's stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

All user-facing natural language in the module docstring and runtime messages is exclusively in French, including usage, status output, and follow-up questions. The file does not offer a language choice or explain that the skill is intentionally limited to French users or a France-specific compliance context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code physically copies input PDFs into a client directory structure and later persists derived metadata into clients.json, _index.json, and _report.json. Although the module docstring describes outputs, there is no explicit safety warning that running the script will duplicate potentially sensitive invoices and bank statements onto disk and create persistent indexes/reports containing extracted financial data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a skill that receives, extracts, names, classifies, and infers client data from accounting documents. This file instead validates invoice JSONs against legal mandatory mentions and 2026 reform rules, which is a separate compliance-checking/auditing capability not justified by the declared purpose of document organization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This manifest-style JSON contains user-facing labels and comments exclusively in French, such as company fields, invoicing labels, and setup instructions. Under the language policy rule, forcing a specific language without user opt-in or documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON contains user-facing natural-language labels, conditions, and texts exclusively in French, but the file does not indicate that the skill is France-specific or that users can opt into this locale. Under the policy rule, forcing a specific language without user choice can be a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

Le fichier présente toute sa documentation CLI, ses messages d'usage et son interface textuelle en français uniquement. Comme SQP-3 couvre les violations de politique linguistique sur tous types de fichiers, cette contrainte de langue sans opt-in utilisateur constitue une violation naturelle de politique de locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Les chaînes affichées à l'utilisateur via console.error et console.log sont systématiquement en français sur l'ensemble du script. En l'absence d'une option de langue, d'un opt-in, ou d'une justification explicite d'un périmètre régional, cela correspond à une violation de politique linguistique selon SQP-3.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.