Back to skill

Security audit

Official Xero skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Xero accounting CLI guide with meaningful confirmation steps for sensitive financial actions.

Install this only if you want an agent to work with your Xero organisation. Prefer read-only scopes when possible, confirm the active organisation/profile before use, approve every write carefully, keep token storage in the OS keychain when available, and review any npm or sudo install command before running it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill enables persistent OAuth authentication and stored tokens for a financial system, including optional file-backed key storage and offline access. In the context of accounting APIs, long-lived session material can expose sensitive financial data and allow ongoing unauthorized actions if the host, profile, or token files are compromised.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
# xero CLI

You have access to the `xero` CLI — a command-line tool for the Xero accounting API using PKCE OAuth. Use it to read and write accounting data in the user's Xero organisation.

## Authentication & Setup

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
75% confidence
Finding

The skill instructs users to run a privileged package installation command (sudo apt install ...) as part of troubleshooting. While not inherently malicious, agent-provided root-level commands increase the chance of unsafe privilege escalation habits, unintended system modification, or misuse in environments where package sources or command context are not verified.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
**If the user is on WSL, SSH, or a headless VM** and sees an encryption-key error after a successful `xero login`:

1. **Prefer fixing the keychain:** `sudo apt install gnome-keyring libsecret-tools dbus-x11`, start `gnome-keyring-daemon`, then `xero login` again.
2. **Flaky keychain** (login OK, next command fails): `export XERO_KEYRING_FILE_BACKUP=1` before `xero login` — mirrors the key to `~/.config/xero-command-line/.encryption-key` (0600) for later reads. Opt-in; weaker than keychain-only.
3. **No keychain:** `export XERO_KEY_STORAGE=file` before `xero login`.
4. **Stronger file-based option:** `export XERO_TOKEN_PASSPHRASE='…'` (same value every session) — scrypt-derived key, not stored in plaintext.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
Before executing **any** commands (including read-only operations), you **must** verify which Xero organisation is active:

1. **Always run `xero org details` at the start of a session** and display the organisation name to the user before executing any other commands. Do not proceed until the user confirms this is the correct org.
2. **Use `-p <profile>` explicitly** when the user has specified or confirmed which profile/org to use. Do not silently rely on the default profile or environment variables without confirmation.
3. **Warn the user if `XERO_PROFILE` or `XERO_CLIENT_ID` environment variables are set**, as these silently override the default profile and may connect to an unintended organisation. Check with `echo $XERO_PROFILE $XERO_CLIENT_ID` if in doubt.
4. **Never switch profiles or call `xero profile set-default`** without explicit user instruction. Changing the default profile affects all subsequent commands and other tools sharing the same config.

Static analysis

No suspicious patterns detected.