Back to skill

Security audit

yoooclaw-expense-tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently reads local phone notification files to summarize personal spending, with no evidence of exfiltration, mutation, hidden code, or persistence.

Install only if you are comfortable letting the agent read local phone notification files for the requested dates, including payment, bank, shopping, and transfer notifications. Use explicit prompts such as a specific date range or category to limit what is processed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very broad everyday spending-related phrases, which increases the likelihood of accidental activation during unrelated conversations. Because this skill reads and analyzes phone notification data, misfires can expose or process sensitive financial information without the user clearly intending to invoke the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is designed to ingest and summarize highly sensitive personal financial data from mobile notifications, including bank, payment, shopping, and transfer records, but it does not present a clear privacy notice, consent boundary, or data-handling limitation. In this context, missing transparency and access warnings materially increase the risk of unauthorized or unexpected exposure of private spending patterns and account activity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.