Security audit
Popadex Finance Copilot
Security checks for vulnerabilities and agentic risk
Overview
This is a read-only PopaDex finance helper whose sensitive financial-data access matches its stated purpose.
Install only if you trust PopaDex and the configured PopaDex MCP server with read access to your financial summaries and portfolio exports. The skill itself appears read-only, but the MCP server's permissions and privacy practices still matter.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
