Back to skill

Security audit

Exchange Rate

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple exchange-rate helper whose shell and network behavior is disclosed and aligned with its purpose.

Install this if you are comfortable with the skill running a local shell script that contacts the 60s exchange-rate API. It does not appear to access credentials or local files, but it depends on curl, jq, and network availability.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill description says it queries exchange rates between two currencies, but the documented behavior includes a special mode that returns all rates and relies on an external API without declaring that capability. This mismatch can mislead users or agents about data exposure and runtime behavior, increasing the chance of unauthorized network use or broader-than-expected retrieval.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a shell script but does not declare any tool scope or permissions, which weakens governance and makes it unclear to an agent or reviewer that code execution is required. In practice, this can lead to unintended shell execution and conceal additional capabilities such as network access performed by the script.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script makes an outbound request to a third-party API using user-influenced parameters without any disclosure to the user that network access will occur or that data will be sent to an external service. While the transmitted data is limited to currency codes and not obviously sensitive in this skill, silent external network access can still create privacy, policy, and trust issues, especially in restricted or offline-expected environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.