Back to skill

Security audit

Boj Mcp

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent BOJ statistics helper with a disclosed package install and local caching, but users should treat the unpinned external package as a supply-chain risk.

Before installing, verify that `boj-mcp` is the package you intend to trust, prefer a pinned reviewed version where possible, and run it with normal least-privilege precautions since package installation and execution occur with your user permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party Executable Introduces Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 4 and 76
Vulnerability Type: Unpinned and unauditable third-party dependency
Risk Level: Medium

Vulnerable Code

Line 4:

yaml
metadata: {"openclaw":{"emoji":"🏦","requires":{"bins":["boj-mcp"]},"install":[{"id":"uv","kind":"uv","package":"boj-mcp","bins":["boj-mcp"],"label":"Install boj-mcp (uv)"}],"tags":["japan","boj","central-bank","monetary-policy","mcp","statistics","interest-rates","finance"]}}

Line 76:

markdown
- Python package: `pip install boj-mcp` or `uv tool install boj-mcp`

Technical Analysis

The Skill directs the framework or user to install boj-mcp from a third-party package registry without specifying an exact version, cryptographic hash, signature, or verified source repository. The project contains only SKILL.md; therefore, the installed executable's implementation cannot be audited from the supplied artifact.

Package installation can execute package-controlled build or installation logic, and subsequent documented commands execute the installed boj-mcp binary. Because the package reference is mutable, a compromised maintainer account, registry compromise, malicious future release, or dependency-confusion condition could cause code different from the reviewed behavior to be installed.

The document also states that the tool performs network downloads and local caching. Those capabilities are not inherently malicious, but they increase the importance of verifying the external implementation and restricting its permissions.

Attack Path

  1. An attacker compromises the package publisher, distribution account, registry entry, or an upstream dependency used by boj-mcp.
  2. The attacker publishes a malicious release under the package name accepted by the unpinned installation declaration.
  3. A user or automation framework processes the Skill and runs pip install boj-mcp or uv tool install boj-mcp.

...[truncated 899 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin boj-mcp to an exact, security-reviewed version in both the OpenClaw installation metadata and documented installation commands.
  2. Require cryptographic hashes or verified package signatures where supported by the package manager.
  3. Document and verify the authoritative package registry and source-code repository rather than relying only on the package name.
  4. Review the package source, build configuration, transitive dependencies, network destinations, and local cache behavior before approving it.
  5. Generate and retain a lockfile or equivalent dependency manifest that includes all transitive versions and integrity data.
  6. Run the executable with least privilege, restricting filesystem access, credentials, environment variables, and outbound network access to what BOJ data retrieval requires.
  7. Use automated dependency monitoring and repeat the security review before updating the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Low
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to install the boj-mcp package without pinning a specific version, which makes the installed code dependent on whatever package version is current at install time. That creates a supply-chain risk: a future malicious or compromised release could be pulled automatically, reducing reproducibility and allowing unexpected code execution during installation or use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.