monobank
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches user data from the official Monobank API endpoint (api.monobank.ua).
- [DATA_EXFILTRATION]: Handles sensitive financial information and API tokens. The skill includes specific instructions to ensure privacy by requiring direct API calls, masking card identifiers, and forbidding the storage or logging of tokens.
- [PROMPT_INJECTION]: Ingests external account data from the Monobank API response (Category 8 surface).
- Ingestion points: Client information and jar titles in SKILL.md.
- Boundary markers: Absent.
- Capability inventory: No file-write, subprocess, or network-write capabilities present.
- Sanitization: No validation of API data before formatting.
Audit Metadata