Back to skill

Security audit

Talentir HumanPay

Security checks for vulnerabilities and agentic risk

Overview

The skill openly enables Talentir payouts, but it also gives agents high-impact payment and webhook administration commands without clear approval safeguards.

Install only if you intend agents to have payment authority through Talentir. Use a narrowly scoped API key, keep daily limits low, disable payout auto-approval unless explicitly needed, and require human review for every payout and any webhook creation or deletion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as a payment tool, but it also documents access to team/account information and full webhook management. This broader capability increases the attack surface and can mislead downstream agents or users into granting or using permissions beyond the narrow payout purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

All requests need:

bash
curl -s "https://www.talentir.com/api/v1/..." \
  -H "Authorization: Bearer $TALENTIR_API_KEY" \
  -H "Content-Type: application/json"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill provides ready-to-run examples for creating payouts and deleting webhooks without prominent warnings about financial impact or system changes. In an agent context, this increases the likelihood of unsafe execution because destructive or money-moving actions are normalized as routine examples.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This example sends payout instructions and recipient identifiers to an external service, directly enabling transfer of funds. In the context of an autonomous agent skill, this is dangerous because misuse or prompt-driven execution can cause unauthorized financial transactions and disclosure of recipient data.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

Supported platforms: tiktok, instagram, youtube-channel.

bash
curl -s -X POST "https://www.talentir.com/api/v1/payout" \
  -H "Authorization: Bearer $TALENTIR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This variant also performs an external payout request and additionally includes tags and custom identifiers that could expose business metadata. The main risk is still unauthorized financial transfer, amplified by the richer metadata being transmitted externally.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Create a payout with tags and custom ID

bash
curl -s -X POST "https://www.talentir.com/api/v1/payout" \
  -H "Authorization: Bearer $TALENTIR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Webhook creation and deletion are administrative capabilities unrelated to simple direct payments and can materially alter account integrations. An agent with this skill could add exfiltration endpoints or remove legitimate monitoring/integration hooks, causing data leakage or operational disruption.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

Creating a webhook transmits configuration to an external service and establishes a persistent outbound event channel to a target URL. If abused, this can redirect sensitive payout event data to attacker-controlled infrastructure and create durable exfiltration paths.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

Create a webhook

bash
curl -s -X POST "https://www.talentir.com/api/v1/webhook" \
  -H "Authorization: Bearer $TALENTIR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The documented preApproved option enables auto-approval of payouts, reducing friction for autonomous money movement. In an agent setting, this meaningfully increases the chance that an unintended or manipulated action results in immediate financial impact without a review checkpoint.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
| `tags`          | No       | Array of strings for categorization                            |
| `customId`      | No       | Your own identifier for the payout                             |
| `notifications` | No       | `allowed` (default) or `not-allowed`                           |
| `preApproved`   | No       | `true` to auto-approve (requires `payout.api_approve` permission) |

## Payout Statuses

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Team information access exceeds the stated payment-focused purpose and exposes organizational metadata that may aid reconnaissance. While less severe than payout or webhook actions, it still broadens available sensitive information without clear necessity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.