Back to skill

Security audit

Agent Passport

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent agent identity and governance purpose, but its setup path runs mutable npm/MCP code and can persist local agent/editor configuration and key material without enough scoping detail.

Review this skill carefully before installing. Prefer pinned package versions, inspect the npm packages before running npx, run setup only in a least-privilege environment, protect .passport/agent.json like a private key, exclude it from version control, and verify exactly what Claude Desktop or Cursor configuration is changed before enabling the MCP server.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:44
Finding

Unpinned Third-Party npm Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:44-48, SKILL.md:58-62, and SKILL.md:96
Vulnerability Type: Unpinned third-party dependencies and direct execution of remotely retrieved npm packages
Risk Level: Medium

Vulnerable Code

SKILL.md:44-48

bash
npm install agent-passport-system        # SDK: /core subpath is the curated default
npm install agent-passport-system-mcp    # MCP server: APS_PROFILE=essential is the default
go get github.com/aeoess/agent-passport-go@v0.7.0   # Go SDK, byte-parity subset (passport, delegation, attribution, completion, in-toto, values)
pip install agent-passport-system==3.0.1             # Python SDK
cargo add agent-passport-system@0.3.0                # Rust SDK, library crate agent_passport

SKILL.md:58-62

bash
npx agent-passport-system-mcp

Remote MCP (zero install): https://mcp.aeoess.com/sse

SKILL.md:96

text
Setup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)

Technical Analysis

The npm installation instructions do not pin agent-passport-system or agent-passport-system-mcp to exact versions and do not provide an integrity hash, signature-verification procedure, or committed lockfile. Consequently, the installed implementation is determined by mutable npm registry state at installation time rather than by the reviewed artifact.

The npx agent-passport-system-mcp and npx agent-passport-system-mcp setup commands present a more direct supply-chain risk because npx can download and immediately execute the package selected from the registry. Package CLI code and applicable npm lifecycle behavior execute with the permissions of the user running the command.

The setup variant is documented as automatically modifying Claude Desktop and Cursor configuration. If the retrieved package were compromised, this configuration access could be abused to register attacker-controlled age ...[truncated 2465 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every npm dependency and npx invocation to an exact reviewed version, for example:

    bash
    npm install --save-exact agent-passport-system@6.0.1
    npm install --save-exact agent-passport-system-mcp@6.0.1
    npx --yes agent-passport-system-mcp@6.0.1
    
  2. Commit an npm lockfile containing registry integrity metadata and require reproducible installation through npm ci rather than unconstrained npm install.

  3. Verify npm package provenance, publisher identity, signatures or attestations, and expected integrity hashes before execution. Document the verification procedure alongside the installation commands.

  4. Prefer installing and reviewing the pinned package before invoking its CLI rather than allowing npx to retrieve and execute an implicitly selected release in one step.

  5. Disable lifecycle scripts during dependency retrieval where compatible with package operation:

    bash
    npm ci --ignore-scripts
    

    If scripts are required, enumerate and review them before enabling execution.

  6. Run the MCP server and setup process in a least-privilege environment without unnecessary credentials, sensitive environment variables, or access to unrelated user files.

  7. Replace automatic editor configuration with a preview-and-confirm workflow. Display the exact files and configuration entries that will be modified, create backups, and require explicit user approval before applying changes.

  8. Publish or reference the corresponding source revision and build provenance for each released package so reviewers can associate the pinned registry artifact with auditable source code.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to execute an MCP server via npx without pinning an exact version, so the code fetched and run can change over time. Because MCP servers operate as tool providers for an agent and may receive sensitive prompts, files, and tokens, a compromised or newly malicious package version could lead directly to code execution or data exfiltration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The command npx agent-passport join --name my-agent --owner alice runs an unpinned package or binary resolution path, which means the executed implementation may differ from what the documentation intended. In this skill, that command also creates identity material, so running an unexpected version could generate insecure keys, leak them, or alter local files unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill says the join step writes .passport/agent.json containing an Ed25519 keypair and signed passport, but it does not place an explicit warning adjacent to the command that this creates sensitive credentials on disk. Users may run it casually in insecure directories, commit the file to source control, or expose it to other local processes, resulting in credential theft and impersonation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This delegation example invokes npx agent-passport without a pinned version, allowing arbitrary changes in the downloaded code path over time. Since the command produces signed delegation artifacts governing authority and spend limits, an altered package could silently widen scope, leak keys, or forge misleading receipts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The unpinned npx agent-passport work ... example permits execution of whatever package version is current at run time rather than a reviewed version. In a workflow centered on signed accountability records, that creates supply-chain risk and could falsify or exfiltrate operational metadata.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The proof-generation example again relies on an unpinned npx execution path. Because this command handles contribution and proof material, a malicious or compromised future release could tamper with proofs, leak attribution data, or write unexpected files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

npx agent-passport-system-mcp setup combines unpinned remote code execution with an operation that modifies local application configuration. That is especially risky because a changed package version could alter Claude Desktop or Cursor settings, add unreviewed servers, or persist unsafe configuration on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup instruction advertises automatic configuration of Claude Desktop and Cursor without clearly warning that it will modify user settings files. Silent or poorly explained config mutation is dangerous because it can persist remote MCP endpoints, alter trust boundaries, and cause users to authorize tools they did not manually review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.