Kontomatik

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Kontomatik banking-data integration, but it gives agents broad authenticated access to sensitive financial data without enough user-control safeguards.

Install only if you trust Membrane and Kontomatik for this financial-data workflow. Use it for specific Kontomatik banking tasks, prefer predefined read-only actions, confirm before any proxy or mutating request, avoid exposing raw account or transaction data in outputs, and revoke the connection when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill recommends direct proxy requests to the Kontomatik API without any warning to minimize, review, or avoid sending unnecessary sensitive financial data. In a banking-data context, this increases the risk that an agent may transmit account, balance, statement, or transaction data through generic requests without user awareness, data minimization, or endpoint-level safety guidance.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal