Back to skill

Security audit

Spraay × Bankr

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Bankr-to-Spraay payment workflow for user-confirmed onchain batch payouts, with financial risk but no hidden or deceptive behavior found.

Install only if you intend to let an agent prepare Bankr-funded Spraay batch payments. Before any execution, verify the recipient list, token, amounts, total cost, chain, and transaction estimate yourself; treat the Bankr API key as control over real funds.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The phrase "split fees" is ambiguous and may apply to many non-crypto or unrelated fee-sharing scenarios, yet this skill is capable of orchestrating real onchain distributions from a Bankr-managed wallet. In a financial automation context, underspecified triggers increase the risk of the wrong skill being selected and presenting or initiating an inappropriate payout workflow.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The phrase "split fees" is ambiguous and may apply to many non-crypto or unrelated fee-sharing scenarios, yet this skill is capable of orchestrating real onchain distributions from a Bankr-managed wallet. In a financial automation context, underspecified triggers increase the risk of the wrong skill being selected and presenting or initiating an inappropriate payout workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.