Back to skill

Security audit

Billclaw

Security checks across malware telemetry and agentic risk

Overview

BillClaw is a disclosed finance skill that handles sensitive bank and Gmail data for its stated purpose, with user-directed setup and no artifact evidence of hidden or malicious behavior.

Install only if you are comfortable with @firela BillClaw packages handling bank and Gmail-related data. Enable only the providers you need, review the npm/source provenance for high-trust financial use, and protect or delete the local ~/.firela/billclaw/ data when appropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill claims it is 'safe' and 'local-first' and states that financial data never leaves the machine, yet it explicitly documents integrations with Plaid, GoCardless, and Gmail that necessarily transmit credentials and user data to third-party services. This mismatch can mislead users into granting access under a false privacy model, especially given the sensitive financial and email data involved.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation advertises Gmail bill fetching without a clear warning that the feature may access email contents and metadata and may send information to external APIs during processing or synchronization. In a finance skill, this is particularly sensitive because email inboxes often contain invoices, account numbers, addresses, and other personal financial records.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.