skills/adryanmoldokkr32-pixel/bionicbot-sovereign-elite-skills/financial-api-integrator/Gen Agent Trust Hub
financial-api-integrator
Fail
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructions involve the retrieval and use of highly sensitive API keys and OAuth tokens for Stripe, Revolut, PayPal, and cryptocurrency providers.
- [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection because it ingests external data (invoices and bank statements) to trigger irreversible financial actions. Ingestion points: 'invoice data' and 'bank statement data' specified in SKILL.md. Boundary markers: None mentioned. Capability inventory: 'create_payment', 'initiate_transfer', and currency swap commands. Sanitization: No input validation or sanitization logic is provided.
- [COMMAND_EXECUTION]: The skill directly triggers financial commands based on automated logic monitoring exchange rates and external invoice data, which could be exploited to move funds without sufficient human oversight.
Recommendations
- AI detected serious security threats
Audit Metadata