T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:97- Finding
Sensitive Recipient Financial Data Transmitted to an External MCP Service Without Explicit Consent
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 97-120 and 187
Vulnerability Type: Sensitive financial and personal data disclosure to an external service
Risk Level: HighVulnerable Code
text Pass selected details to MCP as `payout`. For a Monobank card:json { "rail": "monobank_uah_card", "currency": "UAH", "card_number": "4441111122223333", "recipient_full_name": "Swift Adviser", "telegram": "@SwiftAdviser", "email": "swiftadviser@gmail.com" }text For a Monobank IBAN:json { "rail": "monobank_uah_iban", "currency": "UAH", "iban": "UA...", "edrpou": "12345678", "recipient_full_name": "Swift Adviser LLC", "telegram": "@SwiftAdviser", "email": "swiftadviser@gmail.com" }text Use the MCP server: https://mcp-wallet.mandate.md/mcpTechnical Analysis
The skill instructs the agent to resolve recipients from local context, typically
./mandate-wallet/contacts.csv, and submit the resultingpayoutobject to an externally hosted MCP service. Depending on the selected payment rail, this object can contain a bank card number or IBAN, EDRPOU identifier, recipient name, Telegram handle, and email address.The transfer supports the declared payout function, but the instructions do not require the agent to disclose the destination and exact fields to the user or obtain explicit consent immediately before transmission. This weakens the least-privilege boundary between locally held financial records and an externally controlled service.
If the MCP endpoint, its infrastructure, or an authorized operator is compromised or malicious, the submitted data could be retained, correlated, or misused. The reviewed project does not contain executable code or evidence that the endpoint is malicious; the vulnerability is the unconditional disclosure design and lack of a consent and data-minimization control.
...[truncated 1374 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed consent immediately before sending recipient data to the MCP service.
- Display the external destination and enumerate every field that will be transmitted.
- Apply data minimization: send only fields that the selected exchanger and payment rail strictly require.
- Avoid loading or transmitting unrelated fields from the local contacts file.
- Validate that the MCP endpoint is the expected trusted deployment and require authenticated, encrypted transport.
- Document the service's data retention, processing, deletion, and incident-response policies.
- Where supported, use scoped authorization, endpoint pinning, request signing, and auditable transaction identifiers.
- Fail closed if the server's identity cannot be validated or the user declines disclosure.
- Redact bank and identity fields from logs, status messages, telemetry, and error reports.
