Back to skill

Security audit

Bank Credit Memo

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only credit memo writing skill whose sensitive inputs are expected for its banking purpose, but users should handle real borrower data carefully.

Install only if you are comfortable using an AI assistant for bank credit memo drafting. Do not paste real customer, borrower, UBO, or confidential bank data unless your organization has approved this environment for regulated financial information; prefer redacted or synthetic inputs and have qualified credit staff review all outputs.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This README describes a banking credit memo generator handling borrower analysis, ratings, and facility recommendations, but provides no warning or guidance about sensitive financial and customer data. In this context, users are likely to input confidential borrower financials, personally identifiable information, and internal bank assessments into the skill without understanding data handling expectations, increasing the risk of data leakage, policy violations, or regulatory noncompliance.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly solicits highly sensitive corporate borrower information, including financial statements, borrowing history, ownership/UBO data, and qualitative risk information, but provides no guidance on confidentiality, minimization, retention, consent, or secure handling. In a banking context, this can lead users to paste regulated non-public customer information into an AI system without appropriate controls, creating material privacy, bank secrecy, data governance, and regulatory exposure.

Static analysis

No suspicious patterns detected.