Back to skill

Security audit

Операционный директор: работа с банком (скрипт данных)

Security checks for vulnerabilities and agentic risk

Overview

This banking assistant runs only a local demo-data script, but it can present generated financial records and recurring summaries as live account information without a clear warning.

Review this skill before installing it. It appears to be a demo banking assistant, not a real bank integration; do not rely on its balances, restrictions, payment statuses, or recommended actions unless it is changed to clearly label every account response and scheduled report as synthetic demonstration data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:23
Finding

Synthetic banking data is presented as current operational account data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents the skill as a local-script data retriever, but the body instructs the agent to browse external bank and legal websites for procedures. This expands the skill's effective trust boundary and capabilities beyond what the manifest discloses, which can surprise reviewers and users and lead to unvetted network access during financial-support interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text includes broad, conversational phrases like asking whether everything is OK with the account or what news there is with the bank. Because this skill handles sensitive financial data, vague triggers can cause accidental invocation and disclosure of account status in contexts where the user did not clearly intend to access banking information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill recommends sending a daily account summary into chat at 09:00 without warning about the sensitivity of balances, transactions, restrictions, certificates, and authority data. Scheduled posting of financial information into a chat channel can create persistent exposure to unintended recipients, channel-membership drift, and archival leakage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to visit external banking and legal sites even though its stated purpose is to return account information from a local JSON-producing script. In a finance-context skill, unnecessary browsing increases exposure to prompt injection, data leakage through contextual queries, and capability creep into actions not required for the core function.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The summary section repeats loose trigger phrases for producing a full account summary without clear confirmation requirements. In this context, that can increase the chance of over-broad responses that expose balances, transactions, or restrictions when the user's request was ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language docstring presents all user-facing usage instructions exclusively in Russian, and all generated field labels and values are also Russian-language strings. This can violate a language/locale policy when a skill imposes a specific language without giving the user a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.