Back to skill

Security audit

Fidacy Conversation Receipts

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform a disclosed verification/receipt workflow, with no malware or deception signals, but users should understand that verification metadata may involve an external service and public links.

Install only if you are comfortable with a third-party verification service receiving receipt metadata or hashes and with verify links potentially being publicly checkable. Do not include private names, account numbers, medical details, contract identifiers, or other sensitive context in labels or metadata unless the service's retention and visibility terms fit your use case.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill does not clearly warn users that conversation-derived artifacts are sent to an external service and that verification links are publicly checkable. Even if only hashes are transmitted, the existence of public verifiability and externally anchored metadata can create privacy, consent, and data-governance risks, especially in customer support, claims, medical scheduling, or contract-related contexts.

Static analysis

No suspicious patterns detected.