Back to skill

Security audit

FraudLabs Pro

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a normal FraudLabs Pro connector skill, with the main caveat that its activation wording is broader than ideal.

Install this only if you intend the agent to work with your FraudLabs Pro account. Review the connected account permissions, and require clear user intent before actions that affect fraud decisions, order feedback, customer verification, or reseller/account changes.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The instruction to use this skill for ANY FraudLabs Pro request is overly broad and can cause the agent to invoke the skill in contexts where using the connector is unnecessary or inappropriate. In an agentic environment, broad routing language increases the chance of unintended access to connected external systems and may bypass more context-specific safeguards.

Static analysis

No suspicious patterns detected.