Back to skill

Security audit

French Business Analyser

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly disclosed French business lookup skill with paid remote checks, and its sensitive data flows and consent requirements are stated.

Install this if you are comfortable sending French business identifiers, optional IBAN details, and invoice text to the hosted Railway service and paying per call when approved. Keep the approval gates enabled, review the exact cost before paid checks, and self-host for confidential invoices or stricter data-control requirements.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The broad trigger phrases increase the chance of unintended skill invocation in ordinary conversations, which is risky because this skill can initiate paid actions and send sensitive business data such as invoice text or identifiers to a remote hosted service. In an autonomous agent setting, over-broad matching can cause unnecessary external data disclosure, accidental charges, or workflow hijacking before the user clearly intended to use this specific capability.

Static analysis

No suspicious patterns detected.