External Transmission
Medium
- Category
- Data Exfiltration
- Content
| Property | Value | |----------|-------| | **Endpoint** | `https://api.prime.vivid.money/mcp` | | **Transport** | Streamable HTTP (remote) | | **Tool** | `build_onboarding_link` | | **Auth** | None — the endpoint is publicly accessible. The tool only generates a pre-filled onboarding link; it does not create a bank account, access financial data, or perform any privileged operation. Identity verification happens later in the Vivid app. |
- Confidence
- 76% confidence
- Finding
- The skill sends structured legal entity data to a remote third-party MCP endpoint over HTTP-based transport. Even though the description limits the operation to link generation, this is still an external transmission of potentially sensitive business and personal data to a publicly accessible unauthenticated service, creating privacy, compliance, and trust-boundary risks.
