Back to skill

Security audit

Dynamics Partner Advisor

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Dynamics partner search, but its setup runs an unpinned npm package locally and sends potentially sensitive project details to a third-party hosted service.

Review this before installing. Use it only for Dynamics partner searches you are comfortable sending to topdynamicspartners.com, avoid entering confidential budget or project details unless approved, and prefer a pinned or locked installation of the MCP SSE bridge instead of the documented unpinned npx -y command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35–42
Vulnerability Type: Supply-chain risk caused by an unpinned third-party package
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "dynamics-partner-advisor": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-sse", "https://topdynamicspartners.com/api/mcp/sse"]
    }
  }
}

Technical Analysis

The documented MCP configuration runs @modelcontextprotocol/server-sse through npx without specifying an exact package version or verifying package integrity. The -y option automatically approves installation, so users following the instructions may retrieve and execute whichever package release the registry resolves at that time.

Consequently, the locally executed code can change after this skill has been reviewed. A compromised package, maintainer account, publication pipeline, or package registry could cause malicious lifecycle or runtime code to execute with the privileges of the user running the MCP client.

This finding establishes an insecure dependency configuration. It does not establish that the package or hosted endpoint is currently malicious.

Attack Path

  1. An attacker compromises the package maintainer account, package publication pipeline, or upstream registry distribution path.
  2. The attacker publishes a malicious release under the referenced package name.
  3. A user copies the configuration from SKILL.md and starts the MCP client.
  4. npx -y resolves and downloads the unpinned package without interactive approval.
  5. Package lifecycle or runtime code executes locally under the MCP client user's account.
  6. The malicious code can access resources available to that account and interfere with MCP communications.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user who launches the MCP client. Depending on that user's environment, the compromised pa ...[truncated 400 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin @modelcontextprotocol/server-sse to a reviewed, exact version rather than relying on registry resolution of the latest release.
  2. Install the dependency through a package manifest and committed lockfile so that the complete dependency graph is reproducible.
  3. Verify package integrity using the package manager's supported integrity metadata and a trusted registry.
  4. Avoid automatic installation approval with npx -y where practical; require an explicit installation or review step.
  5. Document the expected publisher, exact version, package source, and checksum so users can validate provenance.
  6. Run the MCP process with least privilege in an isolated environment, without unnecessary filesystem access, environment secrets, or credentials.
  7. Establish a controlled dependency-update process that reviews package changes before advancing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description is broad enough to trigger on many normal requests about selecting Microsoft partners, which can cause the agent to invoke this external skill more often than the user likely expects. Because the skill sends queries to a hosted third-party MCP/SSE service, overbroad routing increases the chance that user business requirements, budgets, timelines, or vendor preferences are unnecessarily disclosed to an external system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that it connects to a hosted MCP/SSE endpoint but does not provide a prominent user-facing warning that prompts and project details will be transmitted to an external service. In this context, users may share sensitive procurement information such as implementation scope, budget range, company size, timeline, or required certifications, creating a confidentiality and privacy risk if they are unaware of the data flow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.