T09 · Insecure Skill Coding Practices
- Location
SKILL.md:55- Finding
Raw Sensitive Data Is Disclosed to External Processors Before Sanitization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed remote PII sanitizer, but it sends raw sensitive text to a third-party API and includes autonomous cryptocurrency payment guidance that needs review.
Install only if you are comfortable sending raw input to TrustBoost and its subprocessors before sanitization. Do not use it for secrets, private keys, passwords, regulated records, or zero-transmission environments unless you have separate contractual and technical controls. Do not grant an agent wallet-signing authority or enable automatic USDC payments from this skill; handle billing manually or through a separately approved payment workflow.
SKILL.md:55Raw Sensitive Data Is Disclosed to External Processors Before Sanitization
SKILL.md:88Defective Autonomous Cryptocurrency Payment Guidance Can Cause Unintended Transfers
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: trustboost-pii-sanitizer
version: "2.6.0"
description: Context-aware PII sanitization for autonomous AI agent pipelines. Sanitizes text before LLMs with 5 context modes (legal/financial/medical/code/general), Privacy Budget per agent, and TrustBoost Score for M2M trust verification. Supports EN, ES (LATAM), PT (BR/PT), DE, JA, FR, IT, KO with country-specific patterns (RFC, CUIT, CPF, CNPJ, Personalausweis, マイナンバー, NIR, Codice Fiscale, 주민등록번호). Returns sanitized text, safety_score (0.0-1.0), risk_category (CRITICAL/PRIVATE/SENSITIVE/CLEAN), and context_applied. No SDK required — single POST request. 50 free requests per wallet with tx_hash="TRIAL".
license: MIT
compa
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
## Known Limitations
- **Prompt injection risk:** Malicious text containing instructions like "Ignore previous instructions" could potentially bypass PII redaction. temperature=0 and strict JSON-only output reduce this risk but do not eliminate it entirely.
- **Not suitable for zero-transmission environments:** Raw text is sent to api.trustboost.dev before sanitization occurs.
- **TRIAL is trust-based:** Per-wallet quota tracking is not cryptographically verified.
- **No certified audit:** Evaluation scores are AI-generated, not from a certified security firm.
The metadata declares a remote endpoint for sanitization, meaning the skill is designed to transmit potentially sensitive input off-platform. Because the service processes PII and even mentions credentials/private keys in examples and categories, the external call expands exposure to network interception, third-party compromise, and regulatory noncompliance if used in high-sensitivity environments.
metadata:
author: teodorofodocrispin-cmyk
version: "2.6.0"
endpoint: https://api.trustboost.dev/sanitize
health: https://api.trustboost.dev/health
payment: Solana USDC (149 USDC = 10,000 sanitizations)
trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
The preview endpoint enables sending sample text to a public external service without authentication, which still exposes submitted content to third-party infrastructure. While intended as a demo, it can encourage unsafe testing with real data and normalizes exfiltration of sensitive text outside the agent's environment.
author: teodorofodocrispin-cmyk
version: "2.6.0"
endpoint: https://api.trustboost.dev/sanitize
health: https://api.trustboost.dev/health
payment: Solana USDC (149 USDC = 10,000 sanitizations)
trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
health: https://api.trustboost.dev/health
payment: Solana USDC (149 USDC = 10,000 sanitizations)
trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
autonomy_score: 8.5/10
audit_score: 9.8/10
languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
health: https://api.trustboost.dev/health
payment: Solana USDC (149 USDC = 10,000 sanitizations)
trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
autonomy_score: 8.5/10
audit_score: 9.8/10
languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
health: https://api.trustboost.dev/health
payment: Solana USDC (149 USDC = 10,000 sanitizations)
trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
autonomy_score: 8.5/10
audit_score: 9.8/10
languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
health: https://api.trustboost.dev/health
payment: Solana USDC (149 USDC = 10,000 sanitizations)
trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
autonomy_score: 8.5/10
audit_score: 9.8/10
languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
health: https://api.trustboost.dev/health
payment: Solana USDC (149 USDC = 10,000 sanitizations)
trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
autonomy_score: 8.5/10
audit_score: 9.8/10
languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean
This skill explicitly instructs agents to POST raw user text containing PII to a third-party remote API before sanitization occurs. In the context of a PII-sanitization skill, external transmission is the core behavior, but it still creates a real privacy and compliance risk because sensitive data leaves the local trust boundary and is processed by external infrastructure and a downstream model provider.
curl -X POST https://api.trustboost.dev/sanitize/preview \
-H "Content-Type: application/json" \
-d '{"text": "My name is John Doe, email john@gmail.com, SSN 123-45-6789"}'
This skill explicitly instructs agents to POST raw user text containing PII to a third-party remote API before sanitization occurs. In the context of a PII-sanitization skill, external transmission is the core behavior, but it still creates a real privacy and compliance risk because sensitive data leaves the local trust boundary and is processed by external infrastructure and a downstream model provider.
curl -X POST https://api.trustboost.dev/sanitize/preview \
-H "Content-Type: application/json" \
-d '{"text": "My name is John Doe, email john@gmail.com, SSN 123-45-6789"}'
The primary API request definition instructs agents to send arbitrary text to an external sanitization endpoint, which is a real data-exposure risk given the skill's purpose is to handle sensitive content. The danger is heightened because sanitization happens remotely after transmission, so secrets and regulated data cross trust boundaries before protection is applied.
## API Request
**Endpoint:** `POST https://api.trustboost.dev/sanitize`
**Headers:** `Content-Type: application/json`
Detected: suspicious.prompt_injection_instructions