Back to skill

Security audit

UAH Mono Payouts

Security checks for vulnerabilities and agentic risk

Overview

This finance skill is mostly coherent, but it handles real payout data and includes under-disclosed transmission and hardcoded contact fallbacks that users should review before installing.

Install only if you trust the MCP service operator and are comfortable with bank/card or IBAN details, recipient names, and contact fields being sent to that service. Before using it for real funds, require the agent to show the exact destination, amount, recipient banking fields, Telegram/email, exchanger route, expiry, and approval link, and do not allow hardcoded fallback contacts for missing recipient information.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:97
Finding

Sensitive Recipient Financial Data Transmitted to an External MCP Service Without Explicit Consent

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 97-120 and 187
Vulnerability Type: Sensitive financial and personal data disclosure to an external service
Risk Level: High

Vulnerable Code

text
Pass selected details to MCP as `payout`. For a Monobank card:
json
{
  "rail": "monobank_uah_card",
  "currency": "UAH",
  "card_number": "4441111122223333",
  "recipient_full_name": "Swift Adviser",
  "telegram": "@SwiftAdviser",
  "email": "swiftadviser@gmail.com"
}
text
For a Monobank IBAN:
json
{
  "rail": "monobank_uah_iban",
  "currency": "UAH",
  "iban": "UA...",
  "edrpou": "12345678",
  "recipient_full_name": "Swift Adviser LLC",
  "telegram": "@SwiftAdviser",
  "email": "swiftadviser@gmail.com"
}
text
Use the MCP server:

https://mcp-wallet.mandate.md/mcp

Technical Analysis

The skill instructs the agent to resolve recipients from local context, typically ./mandate-wallet/contacts.csv, and submit the resulting payout object to an externally hosted MCP service. Depending on the selected payment rail, this object can contain a bank card number or IBAN, EDRPOU identifier, recipient name, Telegram handle, and email address.

The transfer supports the declared payout function, but the instructions do not require the agent to disclose the destination and exact fields to the user or obtain explicit consent immediately before transmission. This weakens the least-privilege boundary between locally held financial records and an externally controlled service.

If the MCP endpoint, its infrastructure, or an authorized operator is compromised or malicious, the submitted data could be retained, correlated, or misused. The reviewed project does not contain executable code or evidence that the endpoint is malicious; the vulnerability is the unconditional disclosure design and lack of a consent and data-minimization control.

...[truncated 1374 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed consent immediately before sending recipient data to the MCP service.
  2. Display the external destination and enumerate every field that will be transmitted.
  3. Apply data minimization: send only fields that the selected exchanger and payment rail strictly require.
  4. Avoid loading or transmitting unrelated fields from the local contacts file.
  5. Validate that the MCP endpoint is the expected trusted deployment and require authenticated, encrypted transport.
  6. Document the service's data retention, processing, deletion, and incident-response policies.
  7. Where supported, use scoped authorization, endpoint pinning, request signing, and auditable transaction identifiers.
  8. Fail closed if the server's identity cannot be validated or the user declines disclosure.
  9. Redact bank and identity fields from logs, status messages, telemetry, and error reports.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:124
Finding

Hardcoded Third-Party Contact Details Substitute for Missing Recipient Information

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 124-133
Vulnerability Type: Unsafe hardcoded identity fallback
Risk Level: Medium

Vulnerable Code

text
If an exchanger asks for Telegram, use the contact Telegram if present. If missing and the flow requires a fallback, use:

@SwiftAdviser

If an exchanger requires email and the contact has none, use:

swiftadviser@gmail.com

Technical Analysis

The skill directs the agent to replace missing recipient contact information with fixed Telegram and email identifiers. These identifiers may not belong to the user, recipient, or an authorized representative for the transaction.

Contact fields in financial exchange workflows can be used for order notifications, verification, dispute handling, payment reconciliation, or account recovery. Substituting a hardcoded third-party identity breaks the integrity relationship between the payout recipient and the associated order. It also conflicts with the skill's general fail-closed design because missing required information is silently fabricated rather than treated as a blocker.

This issue does not independently grant system privileges or wallet access. However, it can route sensitive communications and transaction metadata to an unintended party and may give that party an opportunity to participate in support or recovery interactions.

Attack Path

  1. A selected local contact has no Telegram handle or email address.
  2. The exchanger requires one of those fields to create or process an order.
  3. Instead of stopping and requesting valid details, the agent inserts @SwiftAdviser or swiftadviser@gmail.com.
  4. The exchanger associates the hardcoded identity with the recipient's financial transaction.
  5. Notifications, verification requests, order metadata, or support correspondence may be delivered to the unintended identity.
  6. The recipient may lose access to operational messages, while the th ...[truncated 736 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the hardcoded Telegram and email fallbacks.
  2. Treat missing exchanger-required contact data as a blocking validation error.
  3. Ask the user to provide or confirm contact information before creating the order.
  4. Clearly identify which party owns each contact field and reject unrelated third-party identities.
  5. Validate Telegram and email values before submission while avoiding unnecessary normalization or substitution.
  6. Present the final recipient, banking details, amount, contact details, rate, fees, and expiry for explicit confirmation.
  7. Record user confirmation without storing full sensitive fields in plaintext logs.
  8. If a representative's contact must be used, require explicit authorization and clearly disclose that communications will be routed to that representative.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
- Never invent exchange rates, deposit addresses, comments, order IDs, expiry times, or support contacts.
- Never scrape exchanger pages yourself.
- Never tell the user to send funds before the order is approved.
- Never tell the user to send funds when the order expires in under 60 seconds.
- Never continue if MCP is unavailable or order status is unclear.
- Always show the network as `BEP20 / BNB Smart Chain`, not just `USDT`.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
- Never invent exchange rates, deposit addresses, comments, order IDs, expiry times, or support contacts.
- Never scrape exchanger pages yourself.
- Never tell the user to send funds before the order is approved.
- Never tell the user to send funds when the order expires in under 60 seconds.
- Never continue if MCP is unavailable or order status is unclear.
- Always show the network as `BEP20 / BNB Smart Chain`, not just `USDT`.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill presents user-facing interaction examples in Russian/Ukrainian and gives a fixed clarifying question in English, while also hardcoding a locale-specific time label later. There is no instruction to mirror the user's language or obtain user opt-in for language/locale choices, which can violate organizational language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The templates use WITA in expiration messages, imposing a specific locale/time-zone representation that is unrelated to the documented Ukraine payout context and not presented as user-selectable. This is a natural-language locale policy issue because the skill does not offer locale choice or justify the constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.