Back to skill

Security audit

Up Bank

Security checks for vulnerabilities and agentic risk

Overview

This read-only Up Bank skill asks for an API token to show account and transaction data, with no hidden code or install behavior found.

Only install this if you are comfortable letting the agent read your Up Bank account and transaction information after your approval. Use a token only for the current session when possible, approve calls only for information you asked for, and revoke the token when you no longer need the skill.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.