Back to skill

Security audit

Bank Transactions Connector - Europe (PSD2)

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate banking connector, but it asks users to paste a financial API key into chat and allows whole account-source deletion without strong safeguards.

Review this before installing. If you use it, enter the FiBuKI API key only through a trusted secret/configuration UI if available, avoid pasting keys into chat, and rotate or revoke the key if it was exposed. Treat delete_source as a whole account-source deletion and require a clear account/source name and deliberate confirmation before allowing that tool to run.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:23
Finding

Financial API bearer key collected through conversational context

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23-35
Vulnerability Type: Sensitive credential exposure through insecure secret collection
Risk Level: Medium

Vulnerable Code

markdown
> To connect your bank transactions, I need to set up FiBuKI first.
>
> 1. Go to **https://fibuki.com/clawhub-install**
> 2. Create a free account (or log in)
> 3. Go to **Settings > Integrations > AI Agents** and create an API key
> 4. Paste the key back here
>
> Free plan includes 50 transactions/month with full API access.

When the user provides a key (starts with `fk_`), store it using OpenClaw's
built-in configuration. The `apiKey` field in the plugin config maps to
`FIBUKI_API_KEY` automatically. Tell the user to restart OpenClaw to load the key.

Technical Analysis

The Skill explicitly instructs the user to paste a bearer API key into the conversation. Although the key is subsequently intended to be stored through OpenClaw configuration, it first enters the conversational context.

Conversation history, diagnostic telemetry, application logs, browser history, model context, or other components with access to the session may retain the credential. Prefix validation using fk_ only identifies the expected key format; it does not protect the key, verify its ownership, restrict its privileges, or prevent disclosure.

Because the documented API uses the value directly as an authorization bearer token, possession of the key may be sufficient to impersonate the user to the FiBuKI service.

Attack Path

  1. The Skill tells the user to create a FiBuKI API key.
  2. The user pastes the plaintext key into the conversation as instructed.
  3. The key is retained in conversation history, logs, telemetry, or another system that processes agent messages.
  4. An attacker or unauthorized component obtains access to one of those records.
  5. The attacker submits requests to https://fibuki.com/api/mcp ...[truncated 758 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not request that users paste bearer credentials into conversational messages.
  • Direct users to a dedicated masked secret-entry or plugin-configuration interface.
  • Ensure credentials are written directly to an encrypted secret store and never inserted into model context.
  • Redact matching secret patterns from logs, telemetry, error messages, and diagnostic exports.
  • Avoid echoing the key after entry, including partial values unless a non-sensitive fingerprint is used.
  • Support narrowly scoped API keys and request only the permissions required for the selected workflow.
  • Document key revocation and rotation procedures.
  • Prefer short-lived authorization tokens or an OAuth-style authorization flow where supported.
  • If conversational entry cannot be avoided, clearly warn the user about retention risks and immediately remove or redact the original message after secure storage.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:75
Finding

Whole bank-account source deletion lacks mandatory confirmation safeguards

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 75
Vulnerability Type: Unsafe destructive-operation guidance
Risk Level: Medium

Vulnerable Code

markdown
1. **Never delete individual transactions** — only delete via `delete_source` (deletes the whole bank account)

Technical Analysis

The instruction prohibits deletion of individual transactions but presents delete_source, which deletes an entire bank-account source, as the available deletion mechanism. It does not require the Agent to refuse a request to delete an individual transaction, explain that the requested operation is unsupported, preview the scope of deletion, verify the source identifier, or obtain explicit confirmation immediately before execution.

This creates a dangerous semantic substitution: a narrowly scoped deletion request could be translated into a substantially broader destructive operation. The risk is especially significant because bank-account sources may contain many transactions and associated records.

The issue does not demonstrate unauthorized privilege escalation by itself; the deletion remains limited to capabilities granted by the user's FiBuKI key. The weakness is the absence of safety controls around an authorized but destructive operation.

Attack Path

  1. A user asks the Agent to delete an individual transaction or ambiguously requests removal of bank data.
  2. The Agent applies the instruction that deletion must occur through delete_source.
  3. The Agent identifies or infers a source associated with the transaction.
  4. Without a mandatory scope preview and explicit confirmation, the Agent calls delete_source.
  5. The complete bank-account source is deleted rather than the single transaction the user intended to remove.

This path may also be triggered by misunderstood user intent, an incorrect source selection, or untrusted text that induces the Agent to perform a deletion.

Impact Assessm

...[truncated 572 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the instruction with an explicit statement that individual transaction deletion is unsupported and must not be substituted with source deletion.
  • Require a separate, immediate confirmation before every delete_source call.
  • Show the source name, stable identifier, account details, number of affected transactions, and deletion consequences before confirmation.
  • Require the user to confirm the specific source rather than accepting a generic response such as “yes.”
  • Re-fetch the source after confirmation and verify that its identifier still matches the confirmed target.
  • Do not infer deletion authorization from earlier conversation context.
  • Prefer server-supported soft deletion, recovery windows, or one-time confirmation tokens where available.
  • Record a non-secret audit event containing the confirmed target and operation result.
  • Refuse deletion when the request is ambiguous or when source identity cannot be established reliably.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes broad, common financial terms like "bank," "transaction," "receipt," and "invoice," which can cause the skill to activate in many unrelated conversations. Because this skill handles sensitive banking actions and can create/delete sources or modify transaction metadata, unintended invocation increases the chance of accidental exposure of financial data or execution of consequential actions in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill permits destructive deletion via delete_source but does not present a clear, prominent warning or require explicit confirmation in the user-facing guidance. In a banking/accounting context, deleting a source could remove access to an entire bank account's imported transaction set, making accidental invocation or misunderstanding especially damaging.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.