Back to skill

Security audit

Charmie CRM Lite

Security checks for vulnerabilities and agentic risk

Overview

Review recommended: this is a local contacts CRM, but it stores personal contact data in a plaintext database and can update or delete records by name without built-in confirmation.

Install only if you are comfortable with contact records being stored locally in plaintext. Use it for low-sensitivity contact lists, keep the installation directory private, review dependency versions before npm install, and manually confirm the exact contact before asking an agent to update or delete records.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
db.js:5
Finding

Contact PII Stored in an Unencrypted SQLite Database

Content
View full analysis
{ db.run(`CREATE TABLE IF NOT EXISTS contacts ( id INTEGER PRIMARY KEY AUTOINCREMENT, name TEXT NOT NULL, phone TEXT, email TEXT, notes TEXT )`); }); ``` Contact information is inserted without encryption: ```js case 'add_contact': { const { name, phone, email, notes } = args; const result = await db.run( 'INSERT INTO contacts (name, phone, email, notes) VALUES (?, ?, ?, ?)', [name, phone, email, notes] ); return { content: [{ type: 'text', text: `Added contact with ID ${result.lastID}` }] }; } ``` ### Technical Analysis The application stores names, phone numbers, email addresses, and free-form notes directly in `contacts.db` without application-level encryption. The database is created inside the project directory, and the code does not explicitly set or verify owner-only file permissions. SQLite does not encrypt database contents by default. Consequently, any process or account that obtains filesystem read access to the database can recover all stored records using standard SQLite tooling. Free-form notes may contain information more sensitive than the defined contact fields. This issue does not independently grant remote access or elevate privileges. Exploitation requires existing access to the database file, such as access through another compromised local process, permissive directory or umask settings, an exposed backup, or accidental publication of the project directory. ### Attack Path 1. A user adds contacts through the `add_contact` MCP tool. 2. The application writes the contact fields directly to `contacts.db`. 3. An attacker obtains read access to the project ...[truncated 675 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package.json:11
Finding

Non-Reproducible Dependency Installation Without a Lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example trigger phrases are very broad and natural-language-like, such as 'Add John Doe' and 'Search for Mike', which can overlap with ordinary user conversation. This increases the chance of accidental invocation or unintended contact operations when the user did not explicitly mean to use the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill presents itself as a lightweight contact-management CRM, but it advertises broadcast email and WhatsApp tools that are unavailable in the Lite version and direct users to an external upgrade URL. This mismatch is dangerous because it expands the apparent capability surface and can be used for misleading upsell, phishing, or trust manipulation, especially since the URL is delivered through a tool interface rather than ordinary documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The delete_contact and update_contact operations perform immediate destructive changes based only on a provided name, with no confirmation, preview, or disambiguation. In an agent-driven context, this is dangerous because ambiguous names, model mistakes, or prompt injection elsewhere in a workflow could silently modify or delete the wrong records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code opens a local SQLite database and creates or updates persistent data via table creation and exported write operations, but there is no confirmation prompt, logging, comment, or docstring disclosing that the skill writes user data to disk. For code files, persistent file/data writes are safety-relevant when they occur without any visible user warning.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency uses a caret range, so installations may resolve to different future releases within the major version. That weakens build reproducibility and can unexpectedly introduce vulnerable or malicious upstream changes through the software supply chain.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"setup": "node setup.js"
  },
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.0.0",
    "dotenv": "^16.4.5",
    "sqlite3": "^5.1.6"
  }

Unverifiable Dependency: @modelcontextprotocol/sdk has 3 known advisory(ies) (CVE-2026-25536 (@modelcontextprotocol/sdk has cross-client data leak via shared server/transport); CVE-2026-0621 (Anthropic's MCP TypeScript SDK has a ReDoS vulnerability); CVE-2025-66414 (Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protec)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest does not pin @modelcontextprotocol/sdk, and the package family has known advisories including data leakage, ReDoS, and DNS rebinding issues. Without an exact version, it is impossible to verify whether deployed installations are affected, which increases supply-chain and runtime risk for an MCP-based skill.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Using a caret version for dotenv allows non-identical dependency resolution across installs. While common in development, it creates supply-chain uncertainty and can pull in unreviewed changes that affect runtime behavior or security.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
},
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.0.0",
    "dotenv": "^16.4.5",
    "sqlite3": "^5.1.6"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The sqlite3 package is specified with a floating caret range, which reduces reproducibility and can silently introduce risky upstream changes. Because this package interfaces with native code and a database layer, unexpected dependency updates can have meaningful security consequences.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"dependencies": {
    "@modelcontextprotocol/sdk": "^1.0.0",
    "dotenv": "^16.4.5",
    "sqlite3": "^5.1.6"
  }
}

Unverifiable Dependency: sqlite3 has 2 known advisory(ies) (CVE-2022-21227 (Denial-of-Service when binding invalid parameters in sqlite3); CVE-2022-43441 (sqlite vulnerable to code execution due to Object coercion)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

sqlite3 has known advisories, and because the dependency is not pinned, the actual installed version cannot be verified from the manifest alone. In a CRM context handling contact data, a vulnerable database library could lead to denial of service or potentially more severe compromise depending on how the package is used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.