Back to skill

Security audit

BugPack

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for bug fixing, but it asks users to run an unpinned npm server package and lets the agent edit code and update bug state without explicit safety gates.

Install only if you trust the BugPack MCP package source. Prefer pinning `bugpack-mcp` to a reviewed version and reviewing proposed code diffs before allowing the agent to PATCH bug status or update descriptions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Package Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13-17
Vulnerability Type: Supply-chain risk caused by unpinned package execution
Risk Level: Medium

Vulnerable Code:

markdown
Start BugPack server first:

```bash
npx bugpack-mcp
text

### Technical Analysis

The prerequisite directs users to run `npx bugpack-mcp` without specifying an exact, reviewed package version. Depending on the local npm environment, `npx` can retrieve the current package release from the configured registry and immediately execute its lifecycle or runtime code.

The package content can therefore change after this Skill has been reviewed. The instructions do not require a lockfile, integrity verification, trusted registry, provenance check, or validation of the package's official source. Although the audit did not establish that `bugpack-mcp` is malicious, this mutable dependency-execution pattern creates an avoidable supply-chain exposure.

### Attack Path

1. An attacker compromises the npm publisher account, package distribution process, or configured registry, or gains control of the referenced package.
2. The attacker publishes a malicious package release under the same package name.
3. A user follows the Skill prerequisite and executes `npx bugpack-mcp`.
4. `npx` retrieves the mutable package version from the registry.
5. Malicious lifecycle or runtime code executes locally with the privileges of the invoking user.

### Impact Assessment

Successful exploitation could provide arbitrary code execution with the invoking user's permissions. The resulting access could include reading or modifying files available to that user, accessing environment variables and locally available credentials, making network requests, and altering project source code. The Skill itself does not request elevated operating-system privileges, so the direct impact is bounded by the permissions of the user running `npx`.
Remediation
View remediation

Remediation Suggestions

  • Pin bugpack-mcp to an exact version that has been reviewed, rather than resolving the latest mutable release.
  • Install it through a committed lockfile with integrity metadata.
  • Require a trusted npm registry and document the package's verified official publisher and source repository.
  • Verify package provenance, signatures, and integrity before execution where supported.
  • Disable or carefully review dependency lifecycle scripts when feasible.
  • Prefer shipping or vendoring reviewed server code when operationally practical.
  • Run the server with minimal user permissions and isolate it from unrelated credentials and sensitive files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs users to run npx bugpack-mcp without pinning a version or verifying integrity, which causes execution of whatever package version is current at install time. That creates a supply-chain risk: a compromised latest release, typo-squatted package, or unexpected breaking update could execute arbitrary code on the local machine before any bug-tracking workflow begins.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Fix Bug workflow tells the agent to edit source code and then PATCH the bug record to mark it fixed, but it does not require explicit user confirmation before modifying project files or changing external application state. In an autonomous or semi-autonomous agent setting, this can lead to unintended code changes, premature status changes, and trust erosion if the agent acts on incomplete or malicious bug data from the local server.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.