Back to skill

Security audit

MCP Sentinel

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent security-audit purpose, but it tells users to install and run mutable third-party code without pinning or verification.

Install only after choosing a reviewed commit or release and verifying provenance. Prefer running it in a sandbox or container with read-only access to the specific project being audited, and avoid exposing unrelated home-directory files or secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party Source Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22–35
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
If the project does not already include MCP Sentinel, clone and build it:

git clone https://github.com/fasjdas/mcp-sentinel
cd mcp-sentinel
npm install
npm run build

Run an audit:

node dist/cli.js audit /path/to/project

Technical Analysis

The skill instructs the agent to clone the current default branch of an external GitHub repository, install its npm dependency graph, run its build process, and execute the resulting CLI. Neither an immutable commit nor a cryptographically verified release is specified.

The effective code executed by these commands can therefore change after the skill has been reviewed. In addition, npm install may execute package lifecycle scripts from the repository or its transitive dependencies. A compromise of the upstream repository, an unsafe dependency update, or a malicious npm lifecycle script could result in arbitrary local code execution under the invoking user's account.

The external repository and its dependencies are not included in this artifact, so their behavior cannot be validated by this audit.

Attack Path

  1. An attacker compromises the upstream repository, its default branch, or one of its npm dependencies.
  2. The attacker introduces malicious code into a source file, build script, or npm lifecycle script.
  3. An agent follows the documented workflow and clones the mutable upstream repository.
  4. npm install executes a malicious lifecycle script, or npm run build incorporates the malicious source into the generated CLI.
  5. The agent runs node dist/cli.js audit /path/to/project.
  6. The malicious code executes with the permissions of the invoking user and can access resources available in that execution environment.

Impact Assessment

Successful exploitation could provide arbitrary command execu ...[truncated 598 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the external repository to a reviewed immutable commit hash or a signed release tag.
  2. Publish and verify a cryptographic checksum or signature before executing downloaded code.
  3. Require a committed and reviewed lockfile, and use npm ci rather than npm install to prevent unreviewed dependency resolution changes.
  4. Disable dependency lifecycle scripts where feasible, such as with npm ci --ignore-scripts, and explicitly run only reviewed build steps.
  5. Vendor the reviewed scanner source or distribute a reproducible, signed artifact instead of cloning a mutable default branch.
  6. Run the scanner in a sandbox or container with:
    • Read-only access to the narrowest required project directory.
    • No access to unrelated home-directory files or credential stores.
    • No unnecessary network access.
    • A non-privileged user account.
  7. Review dependency provenance and use automated dependency and integrity verification before installation.
  8. Document the exact trusted version, commit, lockfile checksum, and verification procedure in SKILL.md.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase "Use this skill when the user wants to audit ... configuration files for risky command execution, broad filesystem access, inline secrets, or prompt-injection language" is descriptive but does not define clear trigger phrases, exclusions, or boundaries for when this skill should not activate. Because it spans multiple products and broad audit intents, it may overlap with ordinary requests about config review and cause unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.