Back to skill

Security audit

build-mcp-server

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent MCP-server-building guide, but it includes copyable examples that can expose files or public endpoints without enough access-control warning.

Install only if you are comfortable treating this as advanced MCP development guidance. Before copying its scaffolds, add authentication to any public endpoint, restrict file resources to an explicit approved root, reject traversal and absolute paths, validate origins, and pin dependencies for repeatable builds.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/resources-and-prompts.md:48
Finding

Workspace Resource Scaffold Permits Arbitrary Filesystem Reads

Content
View full analysis

Vulnerability Details

File Location: references/resources-and-prompts.md:48-64
Vulnerability Type: Unrestricted file path access / path traversal
Risk Level: Medium

Vulnerable Code

typescript
import { ResourceTemplate } from "@modelcontextprotocol/sdk/server/mcp.js";

server.registerResource(
  "file",
  new ResourceTemplate("file:///{path}", { list: undefined }),
  { name: "File", description: "Read a file from the workspace" },
  async (uri, { path }) => ({
    contents: [{ uri: uri.href, text: await fs.readFile(path, "utf8") }],
  }),
);
python
@mcp.resource("file:///{path}")
def read_file(path: str) -> str:
    return Path(path).read_text()

Technical Analysis

The documented TypeScript and Python resource implementations pass the client-controlled {path} URI component directly to filesystem APIs. Neither implementation resolves the path relative to an approved workspace root, rejects absolute paths or traversal components, canonicalizes the target, or verifies that the resolved file remains inside the intended workspace.

This contradicts the resource description, which states that the handler reads files “from the workspace.” In practice, filesystem access is limited only by the operating-system permissions of the MCP server process.

Because this file is an implementation reference used when building MCP servers, a server generated from the scaffold inherits the unsafe behavior. The vulnerability becomes reachable when an MCP client is allowed to request resources from that generated server.

Attack Path

  1. A developer adopts the documented file:///{path} resource template in an MCP server.
  2. The server is started with access to workspace files and potentially other files readable by its operating-system account.
  3. An unauthorized or malicious MCP client requests a crafted resource URI whose {path} is an absolute path or contains traversal compon ...[truncated 1036 chars]
Remediation
View remediation

Remediation Suggestions

  • Configure an explicit workspace root rather than accepting unrestricted filesystem paths.
  • Parse and decode the resource path once, reject absolute paths, and reject traversal components.
  • Resolve the requested path against the configured root and canonicalize both the root and target.
  • Verify that the canonical target is the root itself or a descendant of it using path-aware containment checks; do not rely on string-prefix comparison alone.
  • Prevent symlink escapes by resolving real paths before opening files or by using platform facilities that constrain filesystem access beneath a directory.
  • Restrict resource access to authenticated and authorized clients where files are not public.
  • Consider exposing opaque resource identifiers or an allowlisted resource catalog instead of raw filesystem paths.
  • Add tests covering absolute paths, encoded traversal, mixed separators, symlink escapes, and sibling directories with similar prefixes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/auth.md (reported line 52)May include surrounding context.

text
┌─────────┐  client_id=https://...  ┌──────────────┐   upstream OAuth   ┌──────────┐
│ MCP host│ ──────────────────────> │ Your MCP srv │ ─────────────────> │ Upstream │
└─────────┘ <─── bearer token ───── └──────────────┘ <── access token ──└──────────┘

Tier 3: OAuth 2.0 via Dynamic Client Registration (DCR)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description lists specific phrases, but also adds the broad condition 'or discusses building something with the Model Context Protocol.' That catch-all trigger is ambiguous and lacks clear scope boundaries or exclusion conditions, which could cause unintended invocation for general discussion rather than a request to use this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly promotes the fastest path to a live public https:// MCP endpoint and even references an authless template, but it does not place a clear warning near the deployment path that the endpoint may be publicly reachable and unauthenticated. In the context of an MCP-building skill, this is more dangerous because users are likely to expose real upstream APIs, tools, and potentially sensitive data through the server without understanding the access-control and privacy implications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Using npx @modelcontextprotocol/inspector without a pinned version pulls whatever package version is current at execution time. That creates a supply-chain and reproducibility risk: a compromised, malicious, or breaking upstream release could be executed in CI or on a developer machine with no review, which is especially relevant in a scaffold intended to be copied verbatim.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The examples demonstrate a resource template that reads arbitrary filesystem paths directly from a URI parameter and returns the contents to the MCP client/model context, with no path restriction, sandboxing, or warning about sensitive file exposure. In a skill specifically intended to help users build MCP servers, this pattern is likely to be copied into production integrations, making accidental exfiltration of secrets, source code, credentials, or host files more likely.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/tool-design.md (reported line 128)May include surrounding context.

md
## Tool annotations

Hints the host uses for UX — red confirm button for destructive, auto-approve for readonly. All default to unset (host assumes worst case).

| Annotation | Meaning | Host behavior |
|---|---|---|

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/tool-design.md (reported line 132)May include surrounding context.

md
## Tool annotations

Hints the host uses for UX — red confirm button for destructive, auto-approve for readonly. All default to unset (host assumes worst case).

| Annotation | Meaning | Host behavior |
|---|---|---|

Rp1

Low
Category
MCP Rug Pull
Confidence
83% confidence
Finding

pip install fastmcp without version pinning installs the latest available release, which can introduce unreviewed code changes, dependency-chain compromise, or non-reproducible builds. In a reference scaffold for building network-exposed MCP servers, users may copy this directly into setup scripts or deployment automation, increasing the chance that an unsafe or incompatible release is consumed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.