Security audit
pontx-open-exchange-rates
Security checks for vulnerabilities and agentic risk
Overview
This skill is a non-executable guide for safely using Open Exchange Rates with caller-held credentials and explicit approval before live reads.
Before installing, be aware that this skill is meant to help an agent work with an exchange-rate provider using your own App ID. Keep that credential in environment variables, review any generated requests before approving live reads, and apply your own financial validation and rounding controls before using rates in transactions.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
