Back to skill

Security audit

Bank Reconciler Pro

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real bank reconciliation skill, but it should be reviewed because it handles sensitive financial records and under-explains external sharing through Feishu.

Install only after confirming how sensitive bank, invoice, and order data will be handled. Use local-only reconciliation unless you explicitly want Feishu sharing, treat exported files in /tmp as confidential financial records, and verify the local PDF parser dependency before processing untrusted PDFs.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README promotes processing highly sensitive financial records and mentions Feishu integration, but provides no warning about handling confidential banking data, data minimization, retention, or risks of sending reconciliation results to external collaboration platforms. In a skill designed for bank statements, the absence of security and privacy guidance increases the chance that users will expose account details, transaction histories, or customer financial metadata through unsafe storage or sharing workflows.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This skill processes bank statements, invoices, and orders, which commonly contain account numbers, names, transaction histories, and other regulated financial data, but it provides no warning about sensitivity, retention, export, or third-party transmission to Feishu. That omission is dangerous because users may upload confidential records without informed consent, and the skill explicitly supports exporting and pushing reconciliation results to external systems.

Static analysis

No suspicious patterns detected.