Back to skill

Security audit

Payments & Banking

Security checks for vulnerabilities and agentic risk

Overview

This banking skill is purpose-aligned but needs Review because it can perform real financial actions, handle bearer tokens and transaction PINs, and delete saved recipients without enough explicit user-control safeguards.

Review this carefully before installing. Only use it with a verified first-party HTTPS API endpoint, understand that the agent may ask for transaction PINs and use bearer-token sessions, and do not allow ambiguous requests for transfers, confirmations, conversions, or recipient deletion without independently checking the exact details first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Error
Location
SKILL.md:19
Finding

Financial Credentials May Be Disclosed to an External Development API

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–23, 42, 50, 61, and 102–106
Vulnerability Type: Sensitive Credential Disclosure
Risk Level: Critical

Relevant code snippets:

markdown
The default API base URL is `https://payment-api-dev.aiotnetwork.io`. All endpoints are relative to this URL.

To override (e.g. for local development):

```bash
export AIOT_API_BASE_URL="http://localhost:8080"
text

```markdown
- `confirm_transfer` — Confirm a pending transfer | `POST /api/v1/bank/transfer/:id/confirm` | Requires auth | Requires transaction PIN
- `confirm_remittance` — Confirm a pending remittance | `POST /api/v1/bank/transfer/remittance/:id/confirm` | Requires auth | Requires transaction PIN
- `confirm_conversion` — Confirm a pending conversion | `POST /api/v1/bank/convert/:id/confirm` | Requires auth | Requires transaction PIN
markdown
- If a tool requires authentication, verify the session has a valid bearer token before calling it.
- If a tool requires a transaction PIN, ask the user for it fresh each time. Never cache or log PINs.
- Never expose, log, or persist secrets (passwords, tokens, full card numbers, CVVs).

Technical Analysis

The skill directs the agent to use an externally hosted development API as its default service while also requiring authenticated sessions and fresh transaction PINs for financially consequential confirmation operations. Consequently, bearer-token authorization data and transaction PINs may be transmitted to infrastructure outside the audited package.

Although the instructions prohibit caching or logging PINs, the package contains no implementation that demonstrates credential isolation, endpoint trust validation, transaction-scoped authorization, certificate pinning, or a mechanism that keeps the PIN outside the agent context. The use of a development-domain endpoint as the default further weakens the expected trust boundary for ...[truncated 2033 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not collect transaction PINs directly in the agent conversation or expose them to the model context.
  • Move transaction authorization to a trusted, browser-hosted confirmation page or secure first-party application where the PIN is entered directly into an isolated payment-provider interface.
  • Replace the development API default with a verified production endpoint and document the service owner, security boundary, and data-processing expectations.
  • Enforce an allowlist of approved HTTPS origins. Reject arbitrary hosts, user-influenced URLs, redirects to unapproved origins, and non-HTTPS configurations outside isolated local testing.
  • Separate development and production configuration so development endpoints cannot be selected in production deployments.
  • Use short-lived, least-privilege, transaction-scoped authorization tokens rather than broadly reusable bearer tokens.
  • Bind every confirmation credential to a specific transaction identifier, amount, currency, recipient, and expiration time. Enforce single use and replay prevention on the server.
  • Ensure PINs and authorization headers are redacted from prompts, traces, telemetry, logs, error messages, and tool-call records.
  • Publish or include the audited tool implementation so request construction, redirect handling, TLS verification, secret handling, and endpoint validation can be independently reviewed.
  • Require explicit user review of the final recipient, amount, currency, exchange rate, and fees through a trusted interface before confirmation.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

The presence of a destructive tool that accepts a path parameter for recipient deletion is not inherently unsafe, but this skill provides no guardrails around validating the target recipient or obtaining explicit user confirmation before deletion. In a natural-language agent context, ambiguous references like 'delete that recipient' or manipulated identifiers could cause deletion of the wrong saved payee, which may disrupt future remittances or aid fraud preparation.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
- `create_recipient` — Save a new remittance recipient | `POST /api/v1/bank/transfer/remittance/recipients` | Requires auth
- `get_recipient` — Get details of a saved recipient | `GET /api/v1/bank/transfer/remittance/recipients/:recipient_id` | Requires auth
- `update_recipient` — Update a saved recipient's details | `PUT /api/v1/bank/transfer/remittance/recipients/:recipient_id` | Requires auth
- `delete_recipient` — Delete a saved recipient | `DELETE /api/v1/bank/transfer/remittance/recipients/:recipient_id` | Requires auth
- `get_conversion_pairs` — Get available currency conversion pairs | `GET /api/v1/bank/convert/pairs` | Requires auth
- `get_conversion_rate` — Get conversion rate between two currencies | `GET /api/v1/bank/convert/rate` | Requires auth
- `initiate_conversion` — Start a currency conversion | `POST /api/v1/bank/convert` | Requires auth

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill exposes high-impact financial and destructive operations such as transfers, remittances, confirmations, and recipient deletion, but it does not explicitly require a user confirmation or warning immediately before those actions. In an agentic setting, this increases the chance of unintended irreversible actions from ambiguous prompts, mis-clicks, or prompt-manipulated execution flows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.