Back to skill

Security audit

Mercury Payments

Security checks for vulnerabilities and agentic risk

Overview

The skill is a clear Mercury payment helper, but it includes high-impact money movement and persistent financial logging with insufficient boundaries.

Review before installing. Use only narrowly scoped Mercury credentials, require explicit human approval for every payment or transfer, avoid internal transfers unless separately authorized, do not store invoice contents or full payment details in general agent memory, and attach invoice PDFs only to recipients who are authorized to receive them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:14
Finding

Write-Capable Mercury Bearer Token Exposed in Process Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:138
Finding

Financial Payment Data Persisted Without Defined Access or Retention Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

Discover account IDs dynamically (do not hardcode organization-specific IDs):

bash
curl -s -H "Authorization: Bearer $TOKEN" "https://api.mercury.com/api/v1/accounts"

Default payment account should be confirmed at payment time.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`

## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

4. Create recipient if needed

bash
curl -s -X POST "https://api.mercury.com/api/v1/recipients" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Requiring invoice PDFs to be attached to every bookkeeping and vendor email by default can disclose sensitive invoice contents, billing details, addresses, and sometimes banking information beyond the minimum necessary audience. This creates unnecessary data exposure and increases the chance of onward forwarding, mailbox compromise, or accidental disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s stated purpose is invoice payment, but it also includes an internal transfer workflow that can move funds between Mercury accounts without invoice-specific controls. Expanding a payment skill to support broader money movement increases the attack surface and creates an opportunity for unauthorized or misdirected transfers under the guise of routine invoice processing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction to always attach the invoice PDF is overbroad and conflicts with workflows, such as internal transfers, that may not have a legitimate invoice artifact. Blanket attachment requirements encourage unnecessary sharing of financial documents and can lead operators or agents to attach unrelated or sensitive files just to satisfy the procedure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.