Back to skill

Security audit

Fulcra Context

Security checks for vulnerabilities and agentic risk

Overview

The skill is a documentation-only Fulcra connector with strong privacy guidance, but it asks users to run unpinned external CLI/MCP packages while handling sensitive health, calendar, location, and file data.

Review before installing. Use this only for private, user-approved Fulcra reads, and prefer pinned, reviewed versions of `fulcra-api`, `fulcra-context-mcp`, and `mcp-remote` or preinstalled trusted tooling. Do not expose tokens, raw records, calendar details, or location data in shared/public contexts, and avoid broad exports unless you have approved the exact destination and retention plan.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:124
Finding

Unpinned Third-Party Packages Are Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:42, 64, 74, 80, 86, 97, 127-129, 140-141; README.md:12, 20, 26, 74-75
Vulnerability Type: Unpinned package execution and supply-chain exposure
Risk Level: Medium

Complete Code Snippets

SKILL.md:62-64:

bash
uv tool run fulcra-api --help

SKILL.md:78-86:

bash
uv tool run fulcra-api auth login --get-auth-url
bash
uv tool run fulcra-api auth login --device-code <DEVICE_CODE> --poll-timeout=5

SKILL.md:124-130:

json
{
  "mcpServers": {
    "fulcra_context": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://mcp.fulcradynamics.com/mcp"]
    }
  }
}

SKILL.md:137-143:

json
{
  "mcpServers": {
    "fulcra_context": {
      "command": "uvx",
      "args": ["fulcra-context-mcp"]
    }
  }
}

README.md:10-12:

bash
uv tool run fulcra-api auth login

README.md:71-77:

json
{
  "mcpServers": {
    "fulcra_context": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://mcp.fulcradynamics.com/mcp"]
    }
  }
}

Technical Analysis

The documented uv tool run, uvx, and npx -y commands can retrieve packages from external registries and execute them locally. The package references do not specify exact versions, hashes, lockfiles, or other integrity constraints. Consequently, the code executed by these commands can change after the skill package has been reviewed.

This creates a supply-chain trust gap: a compromised publisher account, malicious package update, registry compromise, or dependency-resolution attack could cause arbitrary changed code to execute with the privileges of the user or agent process. The risk is elevated because these tools participate in authentication and may process highly sensitive health, biometric, calendar, location, and file data.

The audit found no evidence that the current named packages are malicious. The confirmed issue is the unsafe, unpinned retrieval and executio ...[truncated 1588 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every directly executed package to an exact, reviewed version, such as mcp-remote@X.Y.Z, and use equivalent exact-version syntax for fulcra-api and fulcra-context-mcp.
  2. Use lockfiles and cryptographic hash verification where supported. Commit the lockfile or verified dependency manifest with the reviewed skill release.
  3. Avoid npx -y for security-sensitive installation paths. Require explicit user approval before first-time retrieval and execution.
  4. Prefer preinstalled, reviewed binaries or packages from a controlled environment for workflows that can access private context or authentication state.
  5. Document the expected package registry and prevent fallback to untrusted indexes or registries.
  6. Run retrieved tools with least privilege, isolate them from unrelated credentials and files, and restrict outbound network access to required Fulcra and authentication endpoints where practical.
  7. Establish a dependency update process that reviews source changes and provenance before updating pinned versions.
  8. Re-audit package versions whenever pins are changed, rather than automatically tracking the latest release.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 9)May include surrounding context.

md
### 🔴 High Risk: Token Exposure

**The risk:** Your Fulcra access token is a bearer token. Anyone with it can read all your health data, calendar, and location.

**How it could leak:**
- Agent logs the token to a public file, chat, or social media post

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 96)May include surrounding context.

md
### 🔴 High Risk: Token Exposure

**The risk:** Your Fulcra access token is a bearer token. Anyone with it can read all your health data, calendar, and location.

**How it could leak:**
- Agent logs the token to a public file, chat, or social media post

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

md
### Ingest Boundary

This read-focused skill does not write records. The live OpenAPI surface includes a typed ingest path, `POST /ingest/v1/record/{data_type}`, alongside the generic ingest path. Use `fulcra-annotations` or a dedicated write skill for user-approved writes, and verify the current OpenAPI schema before using typed ingest in custom code.

### Preferences Boundary

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

The README instructs users to execute uv tool run fulcra-api without pinning an explicit package version. This can lead to non-reproducible installs and exposes users to supply-chain risk if a future release is compromised or introduces unsafe behavior, especially because the skill handles sensitive health, calendar, and location data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

This command again references uv tool run fulcra-api without constraining the version, meaning the executed package may change over time. In a docs-first skill, users often copy-paste commands directly, so unpinned execution increases the chance of pulling a malicious or breaking upstream release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

The README encourages running fulcra-api commands from an unpinned package reference. If the package registry, account, or release pipeline is compromised, users could execute attacker-controlled code when following the instructions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

This unpinned command fetches and executes whatever the current fulcra-api package version is at runtime. Because the skill is designed to access highly sensitive personal context data, any supply-chain compromise would have elevated privacy and credential exposure consequences.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

The documented sleep-stages example relies on an unpinned package version, which creates a supply-chain and reproducibility weakness. Since this skill is explicitly intended for biometrics and sleep data, compromise could expose especially sensitive personal information.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

This calendar-related command invokes an unpinned external tool package. If a malicious update is served, it could execute code in the user's environment and access private calendar context that the skill is otherwise trying to protect.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

The README references metric-time-series --help through an unpinned uv tool run invocation, which still requires resolving and running the package. Even help commands can trigger installation/execution of an unintended or compromised release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

This repeated unpinned package invocation pattern indicates the documentation systematically relies on latest-version execution. In the context of a skill accessing biometrics, activity, calendar, and location data, that makes supply-chain compromise more consequential than in a low-sensitivity tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.