Back to skill

Security audit

Pipeline comptable

Security checks for vulnerabilities and agentic risk

Overview

This accounting workflow is mostly purpose-aligned, but it processes sensitive financial documents and executes unverified local scripts in ways that make spoofing or unintended data changes a real review concern.

Install only in a trusted, locked-down OpenClaw skills directory. Avoid using the included run_pipeline.py as written, do not run it as root, and require explicit user review before filing or reconciling accounting documents. Prefer pinning or verifying the sibling component scripts and using a dedicated low-privilege account with access only to the intended inbox and client folders.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/pipeline.py:40
Finding

Unverified execution of sibling skill scripts

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/run_pipeline.py:1
Finding

Current-working-directory script spoofing in pipeline launcher

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description includes very broad natural-language triggers such as "traite les mails reçus", "range tout ce qui est arrivé", and "traite cette note de frais", which can overlap with ordinary user requests and cause unintended activation. In this accounting context, accidental invocation is more dangerous because the workflow can classify documents and trigger downstream processing on financial records without an explicit, narrow confirmation step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that payment reconciliation launches automatically after classification unless the user passes --no-rapprochement, but the user-facing description does not prominently warn that invoking the skill can modify document organization and start additional processing by default. In a bookkeeping workflow, silent automatic classification and reconciliation can alter financial data handling, create mistaken associations, and make unintended actions harder to detect or undo.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The docstring states that the orchestrator 'ne fait que les appeler dans l'ordre' for the listed steps ①–④ and presents only two modes ending in consolidated reporting. However, the implementation later invokes an additional 'rapprochement-paiements' component automatically unless '--no-rapprochement' is passed, which materially extends the pipeline's behavior beyond what the documentation describes.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/pipeline.py (reported line 45)May include surrounding context.

python
def _run(cmd, stdin_obj=None):
    """Lance une brique et renvoie son JSON de sortie (ou {'error': …})."""
    res = subprocess.run([PY, *map(str, cmd)],
                         input=json.dumps(stdin_obj) if stdin_obj is not None else None,
                         capture_output=True, text=True)
    if res.returncode != 0:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code initializes a client root directory and writes a persistent clients.json file, which affects user data storage. Although the module docstring describes the pipeline behavior, there is no explicit warning at the point of execution that running the script will create or modify files under the chosen client root.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

In email mode, the script loads a mail JSON file and forwards it to another component; in inbox mode, it recursively discovers accounting documents and processes them through multiple subprocesses. These operations handle potentially sensitive personal or financial data, but the code provides no visible user disclosure or warning about that data processing.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/pipeline.py (reported line 117)May include surrounding context.

python
def run_rapprochement(clients_root):
    """⑤ Rapproche les paiements une fois les pièces classées. Le moteur retraite
    tout le dossier (cache reconstructible), donc on le lance sur la racine entière."""
    res = subprocess.run([PY, str(RAPPRO), str(clients_root)], capture_output=True, text=True)
    return {"ok": res.returncode == 0, "summary": (res.stdout or res.stderr).strip()}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

At L7 the script invokes pipeline.py via runpy after supplying filesystem paths at L4-L5, which implies operational effects on local data. There is no confirmation prompt, logging/print statement, docstring, or comment in this file explaining that it will run the pipeline against those directories.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, inline usage descriptions, comments, and runtime summary text are written in French only. This imposes a locale-specific interaction model without any indication of user opt-in or alternative language support.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.