Back to skill

Security audit

CheckMCC

Security checks for vulnerabilities and agentic risk

Overview

This is a simple lookup skill that sends merchant or MCC queries to the disclosed CheckMCC API and does not request account access or make financial changes.

Before installing, understand that lookup queries will be sent to check-mcc.com and reward recommendations may be incomplete or outdated. Avoid entering unnecessary personal transaction details, and verify important rewards decisions with your card issuer.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.