Back to skill

Security audit

Операционный директор: работа с банком (API и виджет)

Security checks for vulnerabilities and agentic risk

Overview

This banking skill should go to Review because it can show realistic current-dated synthetic account data without making the demo nature clear to the user.

Install only if you understand this appears to be a demonstration banking assistant, not a real bank integration. It should be changed to show a persistent demo-data warning in every chat and widget response before anyone relies on balances, payment status, restrictions, certificates, or recommended actions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
plugin.py:33
Finding

Synthetic financial records can be presented as current real-world account data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill processes highly sensitive bank-account details, transactions, restrictions, certificates, and powers of attorney, but the description does not warn about privacy sensitivity or encourage cautious disclosure. Without explicit privacy framing, users and integrators may invoke or display the skill in contexts where confidential financial data is overexposed, especially through widgets or broad routing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance includes broad everyday phrases such as 'как дела со счётом' and 'какие новости по банку,' which can overlap with casual conversation and trigger the skill unexpectedly. In a banking skill with access to sensitive account status, unintended activation can expose financial information or cause the model to route a general conversation into a high-sensitivity context without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The instructions are written as a fixed Russian-speaking role and all response guidance assumes Russian output, but the file does not explicitly state that this locale restriction is optional or region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is declared around a single bank-status data tool, but the documentation instructs the agent to perform live web research on banking procedures and legal sources. This expands authority and data flow beyond the declared capability boundary, creating a tool/intent mismatch that can lead to unauthorized browsing, unreviewed external content shaping advice, and possible leakage of sensitive banking context to third-party sites.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, tool description, schema descriptions, and widget labels are written exclusively in Russian, which imposes a specific language on users. The file does not indicate that Russian is optional, user-selected, or required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The documentation establishes a strong local-only rule for definitions and nearby sections emphasize staying within embedded material, but later sections direct the agent to fetch information from external sites for procedures. While this is not a code-level contradiction about execution, it is an intent/documentation divergence inside the skill file about whether external lookup is part of the skill's operating model.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.