T09 · Insecure Skill Coding Practices
- Location
plugin.py:33- Finding
Synthetic financial records can be presented as current real-world account data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This banking skill should go to Review because it can show realistic current-dated synthetic account data without making the demo nature clear to the user.
Install only if you understand this appears to be a demonstration banking assistant, not a real bank integration. It should be changed to show a persistent demo-data warning in every chat and widget response before anyone relies on balances, payment status, restrictions, certificates, or recommended actions.
plugin.py:33Synthetic financial records can be presented as current real-world account data
Suspicious Unicode normalization or mixed-script content
The skill processes highly sensitive bank-account details, transactions, restrictions, certificates, and powers of attorney, but the description does not warn about privacy sensitivity or encourage cautious disclosure. Without explicit privacy framing, users and integrators may invoke or display the skill in contexts where confidential financial data is overexposed, especially through widgets or broad routing.
The invocation guidance includes broad everyday phrases such as 'как дела со счётом' and 'какие новости по банку,' which can overlap with casual conversation and trigger the skill unexpectedly. In a banking skill with access to sensitive account status, unintended activation can expose financial information or cause the model to route a general conversation into a high-sensitivity context without clear user intent.
The instructions are written as a fixed Russian-speaking role and all response guidance assumes Russian output, but the file does not explicitly state that this locale restriction is optional or region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
The skill is declared around a single bank-status data tool, but the documentation instructs the agent to perform live web research on banking procedures and legal sources. This expands authority and data flow beyond the declared capability boundary, creating a tool/intent mismatch that can lead to unauthorized browsing, unreviewed external content shaping advice, and possible leakage of sensitive banking context to third-party sites.
Suspicious Unicode normalization or mixed-script content
The module docstring, tool description, schema descriptions, and widget labels are written exclusively in Russian, which imposes a specific language on users. The file does not indicate that Russian is optional, user-selected, or required for a region-specific compliance reason.
The documentation establishes a strong local-only rule for definitions and nearby sections emphasize staying within embedded material, but later sections direct the agent to fetch information from external sites for procedures. While this is not a code-level contradiction about execution, it is an intent/documentation divergence inside the skill file about whether external lookup is part of the skill's operating model.
No suspicious patterns detected.