Back to skill

Security audit

Moon Banking

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Moon Banking API helper that uses your API key for banking-data lookups, with broad activation wording but no hidden code, persistence, or destructive behavior.

Install this only if you trust Moon Banking and are comfortable letting the agent use MOON_BANKING_API_KEY to make requests to the Moon Banking API. Prefer asking for explicit Moon Banking lookups, and avoid sending private financial details in free-form search queries unless you intend them to go to that provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The invocation guidance is overly broad and instructs the agent to use the skill for 'bank information of any kind,' which can cause unnecessary activation on ordinary financial discussions. In an agent environment, this increases the chance of sending user queries to an external API without clear need or user intent, expanding data exposure and credential use.

Scope Creep

Low
Category
Excessive Agency
Content
- Chain multiple `exec` calls for complex questions.

Use this skill whenever questions or discussions involve bank information of any kind, including, but not limited to, rankings, reviews, country comparisons, customer experiences, or global banking insights.
Confidence
93% confidence
Finding
not limited to

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.