Back to skill

Security audit

算盘

Security checks for vulnerabilities and agentic risk

Overview

This bookkeeping skill is mostly coherent, but it recommends unsafe installation and can change or delete local financial records without clear confirmation safeguards.

Review carefully before installing. Do not run the one-line remote installer unless you trust the upstream repository and have inspected or verified the script. Use explicit confirmation before any command that adds, updates, removes, imports, or exports financial records, especially delete and CSV export commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:17
Finding

Unverified Remote Installer Piped Directly into Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:17
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

bash
curl -sSL https://raw.githubusercontent.com/yinguobing/suanpan/main/install.sh | bash

Technical Analysis

The recommended installation command retrieves install.sh from the mutable main branch of an external personal GitHub repository and immediately executes its contents with Bash.

The command provides no immutable commit or release pinning, checksum verification, cryptographic signature validation, local inspection step, or confirmation before execution. Because the installer is not included in the audited project, its effective behavior cannot be statically reviewed and may change after this Skill has been approved.

This behavior creates a remote code-execution and supply-chain channel. Compromise of the repository owner account, upstream repository, or relevant delivery infrastructure could cause arbitrary attacker-controlled shell commands to run on systems following the installation instructions.

Direct execution of mutable remote code exceeds the minimum privileges necessary for the Skill's stated function of translating natural-language bookkeeping requests into local suanpan CLI commands. The same installation goal can be achieved using a versioned, integrity-verified artifact or an inspectable source build.

Attack Path

  1. An attacker compromises the upstream repository or its maintainer account, or otherwise gains control over the referenced install.sh.
  2. The attacker modifies the script on the mutable main branch to include malicious shell commands.
  3. A user or agent follows the Skill's recommended installation instruction.
  4. curl downloads the attacker's current script without integrity verification.
  5. The shell pipeline passes the downloaded bytes directly to Bash.
  6. Bash executes the malicious commands w ...[truncated 777 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash installation command.
  2. Publish versioned release artifacts through a controlled release process.
  3. Pin downloads to an immutable release version or commit rather than the mutable main branch.
  4. Publish SHA-256 checksums and preferably cryptographic signatures, and require users to verify them before execution.
  5. Separate retrieval from execution so the installer can be inspected:
    bash
    curl -fL -o install.sh "https://example.invalid/releases/vX.Y.Z/install.sh"
    echo "<trusted-sha256>  install.sh" | sha256sum --check -
    less install.sh
    bash install.sh
    
  6. Prefer package-manager installation or reproducible source builds from a pinned tag.
  7. Avoid requiring administrative privileges unless installation into a protected system directory is explicitly requested. Offer a user-local installation path by default.
  8. Include the installer in the review scope or document all filesystem, network, and privilege-sensitive operations it performs.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (10)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping network-fetched content straight into bash is a classic command-chaining anti-pattern that turns documentation into an arbitrary-code-execution path. In the context of a local CLI skill, this is especially dangerous because users may trust the instructions and run them with little scrutiny, granting immediate execution of any malicious payload delivered from the remote source.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

快速安装(推荐)

bash
curl -sSL https://raw.githubusercontent.com/yinguobing/suanpan/main/install.sh | bash

从源码编译

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata says it converts natural-language transaction descriptions into suanpan CLI commands, but the document also instructs on account creation, record deletion/modification, and bulk import. This capability mismatch can cause an agent or user to authorize broader, state-changing operations than the declared scope suggests, increasing the chance of unsafe execution on financial data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description covers broad finance-related language like bookkeeping, spending, income, transfers, and statistics, which can overlap with ordinary conversation rather than a clear request to run commands. This increases the likelihood of unintended activation and command generation against a user's local financial database.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

git clone https://github.com/yinguobing/suanpan.git cd suanpan cargo build --release sudo cp target/release/suanpan /usr/local/bin/

text

## 快速记账流程

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The quick-accounting flow tells the agent to build and execute suanpan add commands but does not clearly warn that these commands write persistent records to the local finance database. In a finance skill, silent persistence is dangerous because users may expect translation or preview, not immediate state changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes destructive and administrative actions such as deleting transactions, updating records, and creating accounts, even though these are not clearly justified by the stated transaction-to-command conversion purpose. In a financial context, this is risky because an over-permissive agent could alter or destroy bookkeeping data based on ambiguous prompts or accidental invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation shows exporting query results to CSV via --output <文件> but does not warn that this writes sensitive financial records to local storage, may overwrite existing files, and can leave confidential data exposed. In this skill context, the risk is elevated because an agent may generate export commands from casual user requests without the user appreciating the persistence and disclosure implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes a destructive suanpan remove command without warning that deletion may be irreversible or recommending users verify the record ID before execution. In a skill that converts natural-language finance requests into CLI commands, this increases the chance of accidental data loss if the agent selects the wrong transaction ID or the user misunderstands what will be removed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and instructional text are entirely in Chinese, which effectively forces a specific language for users reading the skill reference. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The skill recommends fetching and executing a remote install script directly with curl ... | bash, which removes the opportunity to inspect the script before execution. If the remote content, repository, network path, or hosting account is compromised, this leads to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

快速安装(推荐)

bash
curl -sSL https://raw.githubusercontent.com/yinguobing/suanpan/main/install.sh | bash

从源码编译

Static analysis

No suspicious patterns detected.