Back to skill

Security audit

DeepRead Bank Statements

Security checks for vulnerabilities and agentic risk

Overview

This skill sends user-selected bank statement files to DeepRead for extraction, which is sensitive but clearly disclosed and aligned with its stated purpose.

Install only if you are comfortable sending bank statements and API credentials to DeepRead. Review DeepRead's privacy, retention, and compliance terms, use test or redacted documents where possible, and do not upload statements you are not authorized to process.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to upload a full bank statement PDF to an external service, which is a real external data transmission of highly sensitive financial and personal information. Even if this is the advertised purpose of the skill, sending bank statements off-platform creates material confidentiality, privacy, and compliance risk if users are not clearly warned and given strong controls.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

cURL

bash
curl -s -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@statement.pdf" \
  -F 'schema={"type":"object","properties":{"account_holder":{"type":"string"},"closing_balance":{"type":"number"},"transactions":{"type":"array","items":{"type":"object","properties":{"date":{"type":"string"},"description":{"type":"string"},"amount":{"type":"number"}}}}}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This endpoint also uploads the bank statement to an external service, this time for PII redaction, meaning the sensitive document is transmitted before redaction occurs. That reduces the protective value of the redaction step for the initial recipient and still exposes raw banking PII to the third party.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

Bank statements are loaded with PII (names, account numbers, addresses). Before sharing externally or sending to another model, redact with deepread-pii:

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@statement.pdf"

Static analysis

No suspicious patterns detected.