Back to skill

Security audit

tax-doc-collector

Security checks for vulnerabilities and agentic risk

Overview

This tax expense tracker behaves consistently with its stated purpose, but users should protect its plaintext local tax database and exports as sensitive financial records.

Before installing, be aware that this tool stores tax and expense records in plaintext at ~/.tax_docs.json. Use it on a device/account you trust, restrict file permissions where possible, keep secure backups, review exports before sharing them, and be careful with delete because records are removed permanently.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tax_docs.py:124
Finding

Sensitive Tax Records Stored Without Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/tax_docs.py, lines 37 and 124–139
Vulnerability Type: Plaintext sensitive-data storage with ambient file permissions
Risk Level: Medium

Vulnerable Code

python
DB_PATH = os.path.expanduser("~/.tax_docs.json")
python
def load_db():
    if os.path.exists(DB_PATH):
        with open(DB_PATH, "r") as f:
            return json.load(f)
    return {
        "bracket": 22,
        "expenses": [],
        "mileage": [],
        "home_office": None,
    }

def save_db(db):
    with open(DB_PATH, "w") as f:
        json.dump(db, f, indent=2, default=str)

Technical Analysis

The application stores its database in the plaintext file ~/.tax_docs.json. This database can contain sensitive financial and personal information, including tax bracket, transaction amounts, merchants, dates, expense notes, mileage purposes, charitable activity, medical expense categories, and home-office details.

The file is created using Python's ordinary open(..., "w") operation. Its permissions therefore depend on the process's ambient umask; the application neither requests an owner-only mode nor repairs insecure permissions on an existing database. On a system with a permissive umask, or where the file was pre-created with broad permissions, another local user may be able to read the stored records.

The same direct write also truncates and rewrites the live database rather than using a securely permissioned temporary file followed by an atomic replacement. Although the confirmed confidentiality issue is the lack of enforced permissions, atomic replacement would additionally improve integrity and crash safety.

Attack Path

  1. A user invokes a data-changing command such as setup, add, add-mileage, or add-home-office.
  2. The command passes the in-memory database to save_db().
  3. save_db() creates or rewrites ~/.tax_docs.json using permissions derived from the current environment, wit ...[truncated 1107 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create the database with explicit owner-only permissions (0600) rather than relying on the ambient umask.
  2. Check and repair permissions on every load or save so that pre-existing broadly readable files are also protected.
  3. Store the file inside a private application directory with mode 0700.
  4. Write updates to a securely created temporary file in the same directory, flush and synchronize it, and atomically replace the database to reduce corruption and link-race risks.
  5. Reject symbolic links or otherwise verify that the destination is a regular file owned by the current user.
  6. Consider encryption at rest if the threat model includes privileged local users, stolen backups, or offline disk access; restrictive file permissions alone do not protect against those threats.
  7. Clearly document that the database contains sensitive financial data and is otherwise stored in plaintext.

A secure implementation should use low-level creation with mode 0600, such as os.open() with appropriate creation flags, and apply os.chmod(DB_PATH, 0o600) to existing databases after validating ownership and file type.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README encourages users to record, store, and export tax-related financial data, which is inherently sensitive, but provides no warning about privacy, secure storage, backups, local device protection, or risks of sharing exports. In a tax-document skill, omission of basic data-handling cautions can lead users to expose receipts, merchant histories, income-adjacent records, and deductible expense details through insecure files or workflows.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation indicates file read/write behavior via local storage in ~/.tax_docs.json, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and governance gap: users and platforms cannot easily evaluate the skill’s filesystem access expectations, which is especially concerning for a finance/tax skill handling sensitive personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states that sensitive tax data is stored locally in ~/.tax_docs.json but provides only a brief note to keep backups, without warning about privacy, local compromise, shared-user exposure, or the risks of storing unencrypted financial records. Because tax and deduction data can reveal income patterns, charitable giving, business relationships, and potentially audit-sensitive details, insufficient security guidance increases the chance of accidental disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script stores sensitive financial and tax data in a predictable file under the user's home directory without any warning, consent flow, or file-permission hardening. In the context of a tax-document tool, this data can include merchants, notes, categories, and other personal financial records, increasing privacy exposure if the host is shared, backed up insecurely, or accessed by other local processes/users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The delete command permanently removes expense records immediately after receiving an ID, with no confirmation, undo, or backup mechanism. For a tax-records tool, accidental or scripted deletion can destroy evidence needed for compliance, audits, or year-end reporting, making the operational impact more serious than in a low-value note-taking utility.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.