Skills verify-bank-detail-change
๐Ÿ“ฆ

verify-bank-detail-change

v1.0 Content revision r1 Safe ๐ŸŒ Network access

Verify Supplier Bank Detail Changes

Supplier bank change requests can redirect payments to an unverified account. This skill uses Jithox MCP checks to compare IBANs and identify cases requiring independent confirmation.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 74 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "verify-bank-detail-change" from https://skillstore.io/skills/victor-emmanuel-c-verify-bank-detail-change.md and its manifest at https://skillstore.io/api/skills/victor-emmanuel-c-verify-bank-detail-change/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "verify-bank-detail-change". A proposed supplier account matches the trusted stored account, and completed tool checks report a match and valid structure.

Expected outcome:

  • Illustrative summary, not a live tool result.
  • Workflow outcome: no_change, based on the completed account comparison.
  • IBAN structure: valid; account ownership remains unproven.
  • Next step: investigate any email that still insists the account changed.
  • Nothing was paid or changed.

Using "verify-bank-detail-change". The proposed supplier account differs from the stored account, and completed checks report a change with valid IBAN structure.

Expected outcome:

  • Illustrative summary, not a live tool result.
  • Workflow outcome: verify_first.
  • Hold payment and record updates pending independent confirmation.
  • Call a number from existing records and have the supplier read back the full account number.
  • Valid structure does not prove ownership. No callback is claimed, and nothing was paid or changed.

Using "verify-bank-detail-change". The native verification tools are unavailable, so no live checks complete.

Expected outcome:

  • Illustrative summary, not a live tool result.
  • Tool-called status: not_run. Raw results: unavailable.
  • Workflow outcome: verify_first. Account comparison and IBAN validation remain unresolved.
  • Hold payment and record updates; complete the checks and independent confirmation.
  • Nothing was paid or changed.

Security Audit

Safe
v1 โ€ข 10/5/2026 Open versioned report

Six example URLs use public test accounts, and both reconnaissance matches describe safety boundaries rather than system inspection. The live MCP workflow sends supplier IBANs to Jithox, creating an external financial-data disclosure risk without an explicit approval requirement. No evidence found of malicious exfiltration intent, prompt injection, or instructions to execute the example shell commands.

2
Files scanned
130
Lines analyzed
1
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
Use only check_payment_change and verify_iban at https://jithox.com/api/mcp.
Lines 22-28 require sending proposed and stored supplier IBANs to the external Jithox MCP service. This exposes financial identifiers without explicit disclosure approval; no malicious intent is established.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/victor-emmanuel-c-verify-bank-detail-change/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/victor-emmanuel-c-verify-bank-detail-change/security.svg)](https://skillstore.io/skills/victor-emmanuel-c-verify-bank-detail-change?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/victor-emmanuel-c-verify-bank-detail-change?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/victor-emmanuel-c-verify-bank-detail-change/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/victor-emmanuel-c-verify-bank-detail-change.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

victor-emmanuel-c. (2026). verify-bank-detail-change security audit report (audit version 1) [Author version 1.0]. Skillstore. https://skillstore.io/skills/victor-emmanuel-c-verify-bank-detail-change/audits/1

BibTeX citation

@techreport{victor-emmanuel-c-victor-emmanuel-c-verify-bank-detail-change-2026, author = {victor-emmanuel-c}, title = {verify-bank-detail-change security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/victor-emmanuel-c-verify-bank-detail-change/audits/1}, note = {Author version 1.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "verify-bank-detail-change security audit report (audit version 1)" version: "1.0" type: report authors: - name: "victor-emmanuel-c" date-released: "2026-10-05" url: "https://skillstore.io/skills/victor-emmanuel-c-verify-bank-detail-change/audits/1" identifiers: - type: other value: "skillstore:victor-emmanuel-c-verify-bank-detail-change:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
41
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Review a Supplier Change Request

Compare a proposed IBAN against accounting records and hold changed or unresolved accounts for an independent callback.

Check a New Supplier Account

Validate a proposed IBAN, disclose the missing historical comparison, and identify independent confirmation steps before any payment.

Review Conflicting Account Drafts

Check each proposed account separately, retain raw tool results, and distinguish invalid accounts from unresolved changes.

Try These Prompts

Check One Proposed IBAN
Check proposed supplier IBAN [new IBAN] using Jithox MCP. I approve sharing it for this check. Report limitations and next steps; change nothing.
Compare With Trusted Records
Compare [new IBAN] with [stored IBAN] from our accounting records. Supplier country is [country]. I approve sharing these details with Jithox. Report both checks.
Review Several Account Drafts
Check proposed accounts [IBAN A] and [IBAN B] separately against trusted [stored IBAN]. I approve Jithox processing. Preserve raw verdicts and flags. Change nothing.
Prepare a Controlled Review
Review [proposed IBAN] against trusted [stored IBAN] using Jithox; sharing is approved. Preserve raw results, unresolved checks, and callback requirements. Never infer completed checks.

Best Practices

  • Approve external processing of supplier IBANs before using Jithox, and provide only information required by the live tool schemas.
  • Obtain the stored account and callback number from existing trusted records, never from the change request.
  • Preserve actual tool results and unresolved checks; maintain the payment hold until independent confirmation is completed.

Avoid

  • Treating a valid checksum or no_change result as payment approval or proof of account ownership.
  • Using the change email as the trusted source for the old account or callback number.
  • Running the example curl commands or presenting conditional examples as completed live checks.

Frequently Asked Questions

Does this skill pay invoices or update supplier records?
No. It reports checks and next steps without making payments or changing vendor records.
Does a valid IBAN prove that the supplier owns the account?
No. IBAN validation establishes structure and checksum only, not account existence or ownership.
Which external service receives the account details?
The native checks use the Jithox MCP service at jithox.com. Confirm permission to share supplier IBANs before using it.
What happens when no existing account is available?
The skill omits the old account, discloses the missing comparison, and requires independent confirmation before proceeding.
What happens when a tool call fails?
The result remains unknown, not passed or invalid. The workflow stays verify_first, and the affected check is marked not_run.
Can I run the shell commands in the examples?
Agents must use native MCP tools. The example shell commands are maintainer build checks with public test accounts, not live verification results.

Developer Details

License

MIT

Author version

v1.0

Skillstore revision

r1

Version notice

The author-declared version is not valid SemVer.

Ref

0be6750e006665680212ad9cbfba1b18e115834a

Maintenance freshness

10/5/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“ references/

๐Ÿ“„ examples.md

๐Ÿ“„ SKILL.md

View all