📦

Audit History

verify-bank-detail-change - 1 audit

Oct 5, 2026, 10:26 AM

Six example URLs use public test accounts, and both reconnaissance matches describe safety boundaries rather than system inspection. The live MCP workflow sends supplier IBANs to Jithox, creating an external financial-data disclosure risk without an explicit approval requirement. No evidence found of malicious exfiltration intent, prompt injection, or instructions to execute the example shell commands.

2
Files scanned
130
Lines analyzed
2
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
Use only check_payment_change and verify_iban at https://jithox.com/api/mcp.
Lines 22-28 require sending proposed and stored supplier IBANs to the external Jithox MCP service. This exposes financial identifiers without explicit disclosure approval; no malicious intent is established.
Audited by: codex