T09 · Insecure Skill Coding Practices
- Location
SKILL.md:14- Finding
Write-Capable Mercury Bearer Token Exposed in Process Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a clear Mercury payment helper, but it includes high-impact money movement and persistent financial logging with insufficient boundaries.
Review before installing. Use only narrowly scoped Mercury credentials, require explicit human approval for every payment or transfer, avoid internal transfers unless separately authorized, do not store invoice contents or full payment details in general agent memory, and attach invoice PDFs only to recipients who are authorized to receive them.
SKILL.md:14Write-Capable Mercury Bearer Token Exposed in Process Arguments
SKILL.md:138Financial Payment Data Persisted Without Defined Access or Retention Controls
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
Discover account IDs dynamically (do not hardcode organization-specific IDs):
curl -s -H "Authorization: Bearer $TOKEN" "https://api.mercury.com/api/v1/accounts"
Default payment account should be confirmed at payment time.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Prerequisites
- Mercury API token (write access): `$MERCURY_API_TOKEN` or `pass show <vault-path>`
- Auth: `Authorization: Bearer <token>` (Basic auth also works: `token:` base64)
- Base URL: `https://api.mercury.com/api/v1`
## Accounts
Discover account IDs dynamically (do not hardcode organization-specific IDs):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -s -X POST "https://api.mercury.com/api/v1/recipients" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
Requiring invoice PDFs to be attached to every bookkeeping and vendor email by default can disclose sensitive invoice contents, billing details, addresses, and sometimes banking information beyond the minimum necessary audience. This creates unnecessary data exposure and increases the chance of onward forwarding, mailbox compromise, or accidental disclosure.
The skill’s stated purpose is invoice payment, but it also includes an internal transfer workflow that can move funds between Mercury accounts without invoice-specific controls. Expanding a payment skill to support broader money movement increases the attack surface and creates an opportunity for unauthorized or misdirected transfers under the guise of routine invoice processing.
The instruction to always attach the invoice PDF is overbroad and conflicts with workflows, such as internal transfers, that may not have a legitimate invoice artifact. Blanket attachment requirements encourage unnecessary sharing of financial documents and can lead operators or agents to attach unrelated or sensitive files just to satisfy the procedure.
No suspicious patterns detected.