Back to skill

Security audit

CurrencyBeacon

Security checks for vulnerabilities and agentic risk

Overview

The skill appears read-only and non-malicious, but its CurrencyBeacon branding conflicts with its CurrencyScoop connector and credential setup path.

Before installing, confirm with the publisher whether this is intended to use CurrencyBeacon or CurrencyScoop. Do not connect or enter API credentials until the provider identity is clarified. If you proceed, expect read-only exchange-rate actions through OOMOL and avoid running the external CLI installer unless you trust OOMOL's install path.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is branded and described as 'CurrencyBeacon' but actually invokes the 'currencyscoop' connector/service throughout. This kind of service identity mismatch can misroute user requests to the wrong backend, causing data provenance confusion, policy bypass, or unintended disclosure if users or agents rely on the documented provider identity when deciding whether to use the skill.

Static analysis

No suspicious patterns detected.