Back to skill

Security audit

TrustBoost PII Sanitizer

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed remote PII sanitizer, but it sends raw sensitive text to a third-party API and includes autonomous cryptocurrency payment guidance that needs review.

Install only if you are comfortable sending raw input to TrustBoost and its subprocessors before sanitization. Do not use it for secrets, private keys, passwords, regulated records, or zero-transmission environments unless you have separate contractual and technical controls. Do not grant an agent wallet-signing authority or enable automatic USDC payments from this skill; handle billing manually or through a separately approved payment workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:55
Finding

Raw Sensitive Data Is Disclosed to External Processors Before Sanitization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:88
Finding

Defective Autonomous Cryptocurrency Payment Guidance Can Cause Unintended Transfers

Content
View full analysis
= MAX_AUTO_PAYMENT_USDC: execute_autonomous_payment( amount=149, currency="USDC", network="solana", address="giu4VciTkfWJNG1oeP6SzHEJwmabikJSMB91GaFNWE4" ) else: notify_operator("Insufficient balance — configure wallet funding") ``` ### Technical Analysis The example encourages an agent to execute an irreversible 149 USDC cryptocurrency transfer without transaction-time human approval. The purported spending-limit condition is logically defective: ```python if agent_wallet_balance >= MAX_AUTO_PAYMENT_USDC: ``` This condition checks whether the wallet balance is at least the configured limit. It does not check whether the proposed `amount=149` is less than or equal to that limit. For example, if `MAX_AUTO_PAYMENT_USDC` is configured as 10 and the wallet contains 200 USDC, the condition passes and permits a 149 USDC transfer despite the configured limit being 10 USDC. The example also hard-codes the recipient, amount, currency, and network without requiring independent verification at transaction time. Blockchain verification confirms that a transaction occurred; it does not establish that the operator intended the payment or that the amount complied with the operator's policy. Cryptocurrency transfers are generally irreversible. Granting an autonomous agent signing capability is also not necessary for the Skill's core PII-sanitization function and e ...[truncated 1994 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: trustboost-pii-sanitizer
version: "2.6.0"
description: Context-aware PII sanitization for autonomous AI agent pipelines. Sanitizes text before LLMs with 5 context modes (legal/financial/medical/code/general), Privacy Budget per agent, and TrustBoost Score for M2M trust verification. Supports EN, ES (LATAM), PT (BR/PT), DE, JA, FR, IT, KO with country-specific patterns (RFC, CUIT, CPF, CNPJ, Personalausweis, マイナンバー, NIR, Codice Fiscale, 주민등록번호). Returns sanitized text, safety_score (0.0-1.0), risk_category (CRITICAL/PRIVATE/SENSITIVE/CLEAN), and context_applied. No SDK required — single POST request. 50 free requests per wallet with tx_hash="TRIAL".
license: MIT
compa

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 401)May include surrounding context.

md
## Known Limitations

- **Prompt injection risk:** Malicious text containing instructions like "Ignore previous instructions" could potentially bypass PII redaction. temperature=0 and strict JSON-only output reduce this risk but do not eliminate it entirely.
- **Not suitable for zero-transmission environments:** Raw text is sent to api.trustboost.dev before sanitization occurs.
- **TRIAL is trust-based:** Per-wallet quota tracking is not cryptographically verified.
- **No certified audit:** Evaluation scores are AI-generated, not from a certified security firm.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The metadata declares a remote endpoint for sanitization, meaning the skill is designed to transmit potentially sensitive input off-platform. Because the service processes PII and even mentions credentials/private keys in examples and categories, the external call expands exposure to network interception, third-party compromise, and regulatory noncompliance if used in high-sensitivity environments.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
metadata:
  author: teodorofodocrispin-cmyk
  version: "2.6.0"
  endpoint: https://api.trustboost.dev/sanitize
  health: https://api.trustboost.dev/health
  payment: Solana USDC (149 USDC = 10,000 sanitizations)
  trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The preview endpoint enables sending sample text to a public external service without authentication, which still exposes submitted content to third-party infrastructure. While intended as a demo, it can encourage unsafe testing with real data and normalizes exfiltration of sensitive text outside the agent's environment.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
author: teodorofodocrispin-cmyk
  version: "2.6.0"
  endpoint: https://api.trustboost.dev/sanitize
  health: https://api.trustboost.dev/health
  payment: Solana USDC (149 USDC = 10,000 sanitizations)
  trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
  preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
health: https://api.trustboost.dev/health
  payment: Solana USDC (149 USDC = 10,000 sanitizations)
  trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
  preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
  autonomy_score: 8.5/10
  audit_score: 9.8/10
  languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
health: https://api.trustboost.dev/health
  payment: Solana USDC (149 USDC = 10,000 sanitizations)
  trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
  preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
  autonomy_score: 8.5/10
  audit_score: 9.8/10
  languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
health: https://api.trustboost.dev/health
  payment: Solana USDC (149 USDC = 10,000 sanitizations)
  trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
  preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
  autonomy_score: 8.5/10
  audit_score: 9.8/10
  languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 409)May include surrounding context.

md
health: https://api.trustboost.dev/health
  payment: Solana USDC (149 USDC = 10,000 sanitizations)
  trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
  preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
  autonomy_score: 8.5/10
  audit_score: 9.8/10
  languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 413)May include surrounding context.

md
health: https://api.trustboost.dev/health
  payment: Solana USDC (149 USDC = 10,000 sanitizations)
  trial: tx_hash=TRIAL (50 free sanitizations per wallet, no payment required)
  preview: https://api.trustboost.dev/sanitize/preview (3 free requests per IP, no wallet required)
  autonomy_score: 8.5/10
  audit_score: 9.8/10
  languages: English, Spanish, Portuguese, German, Japanese, French, Italian, Korean

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This skill explicitly instructs agents to POST raw user text containing PII to a third-party remote API before sanitization occurs. In the context of a PII-sanitization skill, external transmission is the core behavior, but it still creates a real privacy and compliance risk because sensitive data leaves the local trust boundary and is processed by external infrastructure and a downstream model provider.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

Try it in 10 seconds — no wallet needed

bash
curl -X POST https://api.trustboost.dev/sanitize/preview \
  -H "Content-Type: application/json" \
  -d '{"text": "My name is John Doe, email john@gmail.com, SSN 123-45-6789"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This skill explicitly instructs agents to POST raw user text containing PII to a third-party remote API before sanitization occurs. In the context of a PII-sanitization skill, external transmission is the core behavior, but it still creates a real privacy and compliance risk because sensitive data leaves the local trust boundary and is processed by external infrastructure and a downstream model provider.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

Try it in 10 seconds — no wallet needed

bash
curl -X POST https://api.trustboost.dev/sanitize/preview \
  -H "Content-Type: application/json" \
  -d '{"text": "My name is John Doe, email john@gmail.com, SSN 123-45-6789"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The primary API request definition instructs agents to send arbitrary text to an external sanitization endpoint, which is a real data-exposure risk given the skill's purpose is to handle sensitive content. The danger is heightened because sanitization happens remotely after transmission, so secrets and regulated data cross trust boundaries before protection is applied.

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
## API Request

**Endpoint:** `POST https://api.trustboost.dev/sanitize`

**Headers:** `Content-Type: application/json`

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL.md:401