Back to skill

Security audit

SHrimp Tasks

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed task-manager MCP integration, with a supply-chain caution because it installs an external npm package by npx.

Install only if you trust the SHrimp npm package and publisher, and consider reviewing the package source or npm provenance before running it. Be aware that paired mode can read or modify prompt/provider settings, activity logs, inbox items, and synced task data, while local mode stores tasks under `~/.shrimp/tasks.json` and sends a disclosed anonymous daily ping.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Execution of an Unreviewed Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20-30
Vulnerability Type: Third-party supply-chain exposure through direct npx execution
Risk Level: Medium

Vulnerable Code

markdown
## Setup

```bash
claude mcp add shrimp -- npx @hermitsh/shrimp-mcp@1.0.6

That's it. To upgrade to phone sync later:

bash
npx @hermitsh/shrimp-mcp@1.0.6 pair
text

### Technical Analysis

The installation and pairing instructions use `npx` to retrieve and execute `@hermitsh/shrimp-mcp@1.0.6` from the configured npm registry. The executable package and its source code are not included in the audited project, so its lifecycle scripts, runtime behavior, transitive dependencies, network operations, and filesystem access cannot be verified from this repository.

Pinning the package to version `1.0.6` reduces unintended version drift, but it does not independently verify the package's integrity or provenance. A compromised publisher account, package release, dependency, registry, or local registry configuration could cause external code to execute with the invoking user's privileges.

The documented package capabilities include reading and modifying local task data, optional cloud synchronization, feedback submission, prompt and provider configuration access, activity-log access, and inbox access. These capabilities increase the potential impact if the downloaded package or one of its dependencies is compromised.

This finding does not establish that the named package is malicious. It identifies an unverified supply-chain execution boundary that cannot be fully audited because the executable implementation is absent from the project.

### Attack Path

1. An attacker compromises the npm publisher, a transitive dependency, the package distribution channel, or the registry configured on the victim's system.
2. The victim follows the documented setup or pairing instructions.
3. `npx` retrieves the external package and resolves any required dependencies.
4.
...[truncated 1285 chars]
Remediation
View remediation

Remediation Suggestions

  1. Vendor the exact executable source and dependency metadata into a reviewable release process, or provide a link to reproducible source corresponding to version 1.0.6.
  2. Publish and verify cryptographic integrity information for the package artifact. Use a lockfile with integrity hashes for all transitive dependencies.
  3. Prefer a controlled installation step over implicit download-and-execute behavior. Document how users can inspect the package before execution.
  4. Run installation with lifecycle scripts disabled where compatible, such as by using npm's --ignore-scripts option, and explicitly document any scripts that are genuinely required.
  5. Document the expected npm registry and advise users to verify their registry configuration before installation.
  6. Publish package provenance or signed release attestations and verify them in the installation process.
  7. Document all expected network endpoints, telemetry behavior, files accessed, and data transmitted by local and paired modes.
  8. Run the MCP server with least privilege, restricting filesystem access to required storage paths and limiting network access to documented endpoints.
  9. Separate sensitive paired-mode capabilities from basic local task management and require explicit user authorization before enabling prompt, provider, inbox, or cloud-sync access.
  10. Provide uninstall, data-removal, pairing-revocation, and incident-response instructions.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs installation and execution via npx of a package that is not cryptographically pinned or otherwise fixed to an immutable artifact. Although the command includes a semver version (@1.0.6), this still relies on remote package resolution at runtime and does not protect against registry compromise, republishing attacks, or a malicious dependency chain; executing it gives the package code execution on the host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.