other
- Location
SKILL.md:16- Finding
Unrestricted Sensitive Environment Reconnaissance
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16–34
Vulnerability Type: Sensitive Environment Reconnaissance
Risk Level: MediumVulnerable Code Snippet
markdown ### 1. Discovery Scan - Finds all MCP servers in your environment - Checks agent configurations for MCP connections - Maps external dependencies ### 2. Security Assessment - Validates authentication mechanisms - Checks encryption in transit - Identifies overprivileged scopes ### 3. Configuration Audit - Detects hardcoded secrets - Validates TLS certificates - Checks for insecure defaults ### 4. Data Flow Analysis - Maps what data each MCP can access - Identifies PII/SPII exposure - Checks retention policiesTechnical Analysis
The skill instructs an agent to perform broad infrastructure discovery, inspect agent configurations, identify hardcoded credentials, and map access to sensitive data. These operations may expose MCP endpoints, dependency topology, authentication details, credentials, and PII/SPII.
The instructions do not establish authorization requirements, constrain discovery to an explicit target allowlist, require read-only access, prohibit retrieval of secret values, or define redaction and secure report-handling controls. Consequently, an agent implementing the documented behavior could collect and reproduce sensitive environmental information beyond what is necessary for a narrowly scoped audit.
No executable implementation, external transmission mechanism, privilege-escalation code, or malicious payload was present in the reviewed package. The risk arises from the unrestricted scope and handling requirements in the skill instructions.
Attack Path
- A user or attacker invokes the skill in an environment where the agent can access MCP configuration files or endpoints.
- Following the discovery instructions, the agent enumerates all accessible MCP servers, related configurations, a ...[truncated 1199 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit authorization before beginning discovery or configuration inspection.
- Require users to provide an allowlist of approved directories, configurations, and MCP endpoints.
- Limit operations to read-only checks and explicitly prohibit permission changes or active exploitation.
- Detect the presence and location of secrets without reading or reproducing their complete values.
- Redact credentials, tokens, PII/SPII, internal endpoint details, and other sensitive values from all output.
- Apply data minimization so reports contain only information required to explain and remediate each finding.
- Require confirmation before inspecting configuration files or mapping sensitive-data access.
- Store reports locally using restrictive permissions and define a short retention period.
- Record the authorized scope and clearly identify resources that were excluded or inaccessible.
- Add guidance requiring immediate rotation if a credential is inadvertently exposed during scanning.
