{"data":{"skill":{"slug":"victor-emmanuel-c-verify-bank-detail-change","name":"verify-bank-detail-change","icon":"📦","repo":"https://github.com/victor-emmanuel-c/jithox-mcp/tree/4a878019dc0b25613bd88699fcb707d52726ecd1/skills/verify-bank-detail-change","status":"approved","author":"victor-emmanuel-c","authorVersion":"1.0","skillstoreRevision":1},"audit":{"id":"56fa0cf8-034f-4afb-9bc7-068a4babde2f","skill_id":"2a49fdee-07dd-4cfe-8612-699e425e4078","version":1,"content_hash":"v3:0be6750e006665680212ad9cbfba1b18e115834a:27daf5885291374c613d092d9140ecf40b6d1f2afea66d63799b6662354da3f4:440c4ed755413cd5bb6862e6bb43b6c096bc3f3725f977035b303f79cbdea32c:736b696c6c732f766963746f722d656d6d616e75656c2d632f7665726966792d62616e6b2d64657461696c2d6368616e6765:26076b83e0a3637a01679eeafc2f44da","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Six example URLs use public test accounts, and both reconnaissance matches describe safety boundaries rather than system inspection. The live MCP workflow sends supplier IBANs to Jithox, creating an external financial-data disclosure risk without an explicit approval requirement. No evidence found of malicious exfiltration intent, prompt injection, or instructions to execute the example shell commands.","remediation":[{"issue":"The live workflow sends proposed and stored supplier IBANs to an external service without requiring approval for that disclosure.","severity":"low","suggestion":"Disclose the transmitted fields and recipient before checking, require approval under the organization privacy policy, and omit unnecessary supplier information."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"references/examples.md","line_end":16,"line_start":16},{"file":"references/examples.md","line_end":24,"line_start":24},{"file":"references/examples.md","line_end":32,"line_start":32},{"file":"references/examples.md","line_end":52,"line_start":52},{"file":"references/examples.md","line_end":60,"line_start":60},{"file":"references/examples.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":15,"line_start":15}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":15,"line_start":15}],"confidence":0.94,"description":"Use only check_payment_change and verify_iban at https://jithox.com/api/mcp.","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"Lines 22-28 require sending proposed and stored supplier IBANs to the external Jithox MCP service. This exposes financial identifiers without explicit disclosure approval; no malicious intent is established."}],"dangerous_patterns":[],"files_scanned":2,"total_lines":130,"audit_model":"codex","audited_at":"2026-10-05T10:26:56.693+00:00","created_at":"2026-10-05T14:03:03.567897+00:00","static_findings":[{"id":"network:references/examples.md:16:hardcoded-url","file":"references/examples.md","pattern":"Hardcoded URL","snippet":"curl -s https://jithox.com/api/mcp \\","category":"network","line_end":16,"severity":"low","line_start":16},{"id":"network:references/examples.md:24:hardcoded-url","file":"references/examples.md","pattern":"Hardcoded URL","snippet":"curl -s https://jithox.com/api/mcp \\","category":"network","line_end":24,"severity":"low","line_start":24},{"id":"network:references/examples.md:32:hardcoded-url","file":"references/examples.md","pattern":"Hardcoded URL","snippet":"curl -s https://jithox.com/api/mcp \\","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:references/examples.md:52:hardcoded-url","file":"references/examples.md","pattern":"Hardcoded URL","snippet":"curl -s https://jithox.com/api/mcp \\","category":"network","line_end":52,"severity":"low","line_start":52},{"id":"network:references/examples.md:60:hardcoded-url","file":"references/examples.md","pattern":"Hardcoded URL","snippet":"curl -s https://jithox.com/api/mcp \\","category":"network","line_end":60,"severity":"low","line_start":60},{"id":"network:references/examples.md:68:hardcoded-url","file":"references/examples.md","pattern":"Hardcoded URL","snippet":"curl -s https://jithox.com/api/mcp \\","category":"network","line_end":68,"severity":"low","line_start":68},{"id":"network:SKILL.md:15:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Use only check_payment_change and verify_iban at https://jithox.com/api/mcp.","category":"network","line_end":15,"severity":"low","line_start":15},{"id":"blocker:SKILL.md:43:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"A valid IBAN proves structure/checksum only, not account existence or ownership.","category":"blocker","line_end":43,"severity":"low","line_start":43},{"id":"blocker:SKILL.md:45:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"human next step. State that nothing was paid or changed.","category":"blocker","line_end":45,"severity":"low","line_start":45}],"finding_verdicts":[{"id":"network:references/examples.md:16:hardcoded-url","reason":"Lines 3-7 identify public test accounts and forbid agents from running these maintainer examples. This request compares sample IBANs, not private financial records.","verdict":"false_positive","confidence":0.99},{"id":"network:references/examples.md:24:hardcoded-url","reason":"This maintainer example compares public test accounts using the documented service. Lines 3-7 explicitly prohibit agent execution, so the URL is not an unauthorized transfer instruction.","verdict":"false_positive","confidence":0.99},{"id":"network:references/examples.md:32:hardcoded-url","reason":"The request validates a public sample IBAN, with no secrets or execution payload. Lines 3-7 classify it as a maintainer example that agents must not run.","verdict":"false_positive","confidence":0.99},{"id":"network:references/examples.md:52:hardcoded-url","reason":"This example tests a deliberately broken sample IBAN against a public reference account. Lines 3-7 prohibit agent execution and distinguish expectations from live results.","verdict":"false_positive","confidence":0.99},{"id":"network:references/examples.md:60:hardcoded-url","reason":"The example submits a public test IBAN for checksum validation, not private records. Its maintainer-only status and agent execution prohibition are explicit in lines 3-7.","verdict":"false_positive","confidence":0.99},{"id":"network:references/examples.md:68:hardcoded-url","reason":"The request illustrates a country mismatch using public test accounts and a fictional supplier. Lines 3-7 prohibit running this example as an agent.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:15:hardcoded-url","reason":"Lines 22-28 require sending proposed and stored supplier IBANs to the external Jithox MCP service. This exposes financial identifiers without explicit disclosure approval; no malicious intent is established.","verdict":"confirmed","severity":"low","confidence":0.94},{"id":"blocker:SKILL.md:43:system-reconnaissance","reason":"The sentence limits what IBAN validation proves: structure and checksum, not existence or ownership. It requests no system inspection or reconnaissance.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:45:system-reconnaissance","reason":"This line requires reporting the human next step and stating that nothing was paid or changed. It contains no host discovery or reconnaissance instructions.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"0be6750e006665680212ad9cbfba1b18e115834a","subject_content_hash":"27daf5885291374c613d092d9140ecf40b6d1f2afea66d63799b6662354da3f4","subject_tree_hash":"440c4ed755413cd5bb6862e6bb43b6c096bc3f3725f977035b303f79cbdea32c","subject_plugin_path":"skills/victor-emmanuel-c/verify-bank-detail-change","audit_payload_hash":"26076b83e0a3637a01679eeafc2f44da","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"0be6750e006665680212ad9cbfba1b18e115834a","contentHash":"27daf5885291374c613d092d9140ecf40b6d1f2afea66d63799b6662354da3f4","treeHash":"440c4ed755413cd5bb6862e6bb43b6c096bc3f3725f977035b303f79cbdea32c","pluginPath":"skills/victor-emmanuel-c/verify-bank-detail-change","auditPayloadHash":"26076b83e0a3637a01679eeafc2f44da"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/victor-emmanuel-c-verify-bank-detail-change/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}