Back to skill

Security audit

Starling Bank

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Starling Bank integration, but it gives an agent access to sensitive banking data and money-moving actions without enough safeguards.

Only install after reviewing the MCP package source and provenance, pinning a trusted version, using the narrowest Starling token scopes, storing the token in a protected secret store, and requiring explicit confirmation before any payment, payee change, savings transfer, card change, or display of sensitive account details.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:14
Finding

Unpinned Global Installation of a Privileged Banking Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:25
Finding

Banking Access Token Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:136
Finding

Uncontrolled Persistence of Sensitive Banking Account Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: starling-bank
description: Manage Starling Bank accounts via the starling-bank-mcp server. Check balances, list transactions, create payees, make payments, manage savings goals, and track spending. Use when the user asks about their bank balance, transactions, payments, savings, direct debits, standing orders, or any Starling Bank operation. Requires the starling-bank-mcp npm package and a Starling personal access token.
---

# Starling Bank

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

npm i -g starling-bank-mcp

text

### 2. Get a Personal Access Token

Create one at https://developer.starlingbank.com/ (Personal Access Token with required scopes).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

npm i -g starling-bank-mcp

text

### 2. Get a Personal Access Token

Create one at https://developer.starlingbank.com/ (Personal Access Token with required scopes).

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents high-risk financial operations including payee creation, payments, savings goal deposits/withdrawals, and card lock changes, but does not require an explicit confirmation step or warn about irreversible consequences. In a banking skill, omission of confirmation guidance materially increases the risk of unauthorized or accidental money movement and account changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation text is very broad and could cause the skill to be invoked for many generic banking-related requests without narrowing to safe, user-intended Starling-specific operations. In a banking context, overbroad activation increases the chance of exposing sensitive financial data or initiating account actions when the user did not explicitly request use of this integration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup instructions tell users to create and configure a personal access token in environment settings but provide no warning that the token is a sensitive credential with account access. This can lead to insecure storage, accidental disclosure, excessive scope assignment, or reuse in unsafe environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill enables retrieval of balances, transactions, account identifiers, direct debits, standing orders, and card details without any privacy or data-handling warning. Because banking data is highly sensitive, failing to set explicit expectations around consent, minimization, and display of sensitive fields raises the risk of overexposure of personal financial information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation enumerates financially sensitive and destructive banking operations such as creating payees, sending payments, deleting payees, withdrawing savings, and locking cards without any warning about confirmation requirements, user consent, or the irreversible nature of some actions. In a banking skill, this omission increases the risk that an agent or user triggers high-impact actions too casually, leading to unauthorized transfers, service disruption, or account changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.