Back to skill

Security audit

Mcp Server Scanner

Security checks for vulnerabilities and agentic risk

Overview

This MCP security scanner has a coherent purpose, but it asks for broad environment, configuration, secret, and PII discovery without enough scoping or output-handling safeguards.

Install only if you are comfortable letting the agent inspect MCP-related configurations and report sensitive security findings. Run it against an explicit scope, keep reports local, redact secrets and PII before sharing results, and rotate any credentials that appear in output.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:16
Finding

Unrestricted Sensitive Environment Reconnaissance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–34
Vulnerability Type: Sensitive Environment Reconnaissance
Risk Level: Medium

Vulnerable Code Snippet

markdown
### 1. Discovery Scan
- Finds all MCP servers in your environment
- Checks agent configurations for MCP connections
- Maps external dependencies

### 2. Security Assessment
- Validates authentication mechanisms
- Checks encryption in transit
- Identifies overprivileged scopes

### 3. Configuration Audit
- Detects hardcoded secrets
- Validates TLS certificates
- Checks for insecure defaults

### 4. Data Flow Analysis
- Maps what data each MCP can access
- Identifies PII/SPII exposure
- Checks retention policies

Technical Analysis

The skill instructs an agent to perform broad infrastructure discovery, inspect agent configurations, identify hardcoded credentials, and map access to sensitive data. These operations may expose MCP endpoints, dependency topology, authentication details, credentials, and PII/SPII.

The instructions do not establish authorization requirements, constrain discovery to an explicit target allowlist, require read-only access, prohibit retrieval of secret values, or define redaction and secure report-handling controls. Consequently, an agent implementing the documented behavior could collect and reproduce sensitive environmental information beyond what is necessary for a narrowly scoped audit.

No executable implementation, external transmission mechanism, privilege-escalation code, or malicious payload was present in the reviewed package. The risk arises from the unrestricted scope and handling requirements in the skill instructions.

Attack Path

  1. A user or attacker invokes the skill in an environment where the agent can access MCP configuration files or endpoints.
  2. Following the discovery instructions, the agent enumerates all accessible MCP servers, related configurations, a ...[truncated 1199 chars]
Remediation
View remediation

Remediation Suggestions

  • Require explicit authorization before beginning discovery or configuration inspection.
  • Require users to provide an allowlist of approved directories, configurations, and MCP endpoints.
  • Limit operations to read-only checks and explicitly prohibit permission changes or active exploitation.
  • Detect the presence and location of secrets without reading or reproducing their complete values.
  • Redact credentials, tokens, PII/SPII, internal endpoint details, and other sensitive values from all output.
  • Apply data minimization so reports contain only information required to explain and remediate each finding.
  • Require confirmation before inspecting configuration files or mapping sensitive-data access.
  • Store reports locally using restrictive permissions and define a short retention period.
  • Record the authorized scope and clearly identify resources that were excluded or inaccessible.
  • Add guidance requiring immediate rotation if a credential is inadvertently exposed during scanning.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly performs environment discovery, configuration inspection, dependency mapping, and data flow analysis, which can expose sensitive infrastructure details, secrets, and regulated data if users are not clearly warned or prompted for consent. In a security-scanning context this behavior is expected, but the absence of prominent warnings, scope limitations, and handling guidance increases the risk of over-collection and accidental disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.