Back to skill

Security audit

Mcp Server

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to provide quantitative finance tools, but it relies on mutable remote services and exposes a broad unauthenticated local MCP server in ways users should review before installing.

Install only if you are comfortable sending calculation inputs to QuantOracle's remote backend and exposing an MCP HTTP service from the host. Prefer a pinned package version, run it bound to localhost or behind authentication, restrict the backend URL to a trusted origin, and avoid submitting sensitive trading, portfolio, or client data unless the provider's data handling terms are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
src/index.ts:172
Finding

Remote OpenAPI Metadata Can Inject Mutable Agent-Facing Instructions

Content
View full analysis
({ tools: toolDefs.map((t) => ({ name: t.name, description: t.description, inputSchema: t.inputSchema, annotations: { title: t.description.split(".")[0], readOnlyHint: true, destructiveHint: false, idempotentHint: true, openWorldHint: false, }, })), })); ``` The compiled equivalent is present in `dist/index.js:135-160`. ### Technical Analysis The effective MCP tool manifest is not bundled with the reviewed package. It is downloaded from `BACKEND_URL` at every startup, and remote `description`, `summary`, path, and schema content is incorporated into Agent-facing MCP metadata without integrity verificatio ...[truncated 1994 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/index.ts:343
Finding

Unauthenticated Public MCP Service Has Spoofable Rate Limiting and Unbounded Session Retention

Content
View full analysis
(); function getClientIP(req: express.Request): string { return ( (req.headers["x-forwarded-for"] as string)?.split(",")[0]?.trim() || (req.headers["x-real-ip"] as string) || req.ip || req.socket.remoteAddress || "unknown" ); } ``` New sessions are accepted without authentication or a session limit and are retained until their transport closes: ```typescript app.post("/mcp", async (req, res) => { const sessionId = req.headers["mcp-session-id"] as string | undefined; if (sessionId && transports.has(sessionId)) { await transports.get(sessionId)!.handleRequest(req, res); return; } // New session const clientIP = getClientIP(req); let capturedSid: string | undefined; const transport = new StreamableHTTPServerTransport({ sessionIdGenerator: () => { capturedSid = crypto.randomUUID(); return capturedSid; }, onsessioninitialized: (sid: string) => { transports.set(sid, transport); }, }); transport.onclose = () => { if (capturedSid) { transports.delete(capturedSid); sessionIPs.delete(capturedSid); } }; const server = createServer(clientIP, capturedSid || "pending"); await server.connect(transport); await transport.handleRequest(req, res); // Update session ID mapping after transport assigns it if (capturedSid) { sessionIPs.set(capturedSid, clientIP); } }); ``` The service is exposed on every network interface: ```typescript app.listen(PORT, "0.0.0.0", () => { consol ...[truncated 2502 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Documentation Executes an Unpinned Package Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Yes, this is a mismatch. The description promises a large set of quantitative finance functions, but the actual code chunk contains only an empty module declaration (export {}) and no executable logic or type declarations exposing those capabilities. There are no signs of finance computations, MCP handlers, triggers, or supporting infrastructure. Based on the provided code alone, the declared purpose is not accurately represented.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

fast-uri 3.1.0 is present transitively and is reported with multiple URI parsing flaws including host confusion and possible SSRF-enabling edge cases. For an MCP/HTTP-facing service, URL parsing inconsistencies can be dangerous if any component validates or routes based on parsed hosts, even if the current skill appears focused on deterministic finance calculations rather than outbound URL fetching.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: hono==4.12.10 — 16 advisory(ies): CVE-2026-56762 (Hono missing validation of cookie name on write path in setCookie()); CVE-2026-47676 (Hono: app.mount() strips mount prefix using undecoded path, causing incorrect ro); CVE-2026-47675 (Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie) +13 more

High
Category
Supply Chain
Confidence
87% confidence
Finding

hono 4.12.10 is present with a large number of advisories affecting cookie handling, routing, and path processing. Since Hono underpins the transitive MCP SDK server stack, these issues represent real inherited risk, especially in a network-exposed service where malformed paths or headers may reach framework code before application logic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
80% confidence
Finding

ip-address 10.1.0 is a transitive dependency of express-rate-limit and is flagged for address parsing inconsistencies and XSS in HTML-emitting methods. The XSS portion is likely not relevant unless those HTML helpers are used, but address parsing ambiguity can matter in IP-based access control or rate limiting, potentially weakening protection logic.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises executable/networked MCP usage but does not declare any explicit tool scope or permission boundaries. In agent environments, missing scope declarations can allow broader-than-necessary access to network or environment-backed capabilities, increasing the blast radius if the package or remote MCP endpoint behaves unexpectedly or maliciously.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx quantoracle-mcp without a pinned version causes installation/execution of whatever package version is current at runtime. This creates a supply-chain risk: a compromised maintainer account, malicious update, or dependency hijack could cause agents to fetch and run unreviewed code with the skill's available privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool forwards all user-supplied arguments directly to an external backend service, which means prompts, financial inputs, and any accidentally included sensitive data leave the local MCP server boundary. In an agent-skill context this is security-relevant because users may assume calculations happen locally, while the skill silently transmits data to a remote API.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · dist/index.js (reported line 361)May include surrounding context.

js
description: "63 deterministic quant computation tools for AI agents. Options pricing, exotic derivatives, risk metrics, portfolio optimization, Monte Carlo, statistics, crypto/DeFi, macro/FX, time value of money. 1,000 free calls/day — no signup required.",
            homepage: "https://quantoracle.dev",
            repository: "https://github.com/QuantOracledev/quantoracle",
            documentation: "https://api.quantoracle.dev/docs",
            license: "MIT",
            keywords: ["finance", "quantitative", "options", "derivatives", "risk", "portfolio", "statistics", "crypto", "defi", "macro", "fx", "backtesting", "deterministic", "calculator"],
            tools: toolDefs.map((t) => ({

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/index.ts (reported line 434)May include surrounding context.

ts
description: "63 deterministic quant computation tools for AI agents. Options pricing, exotic derivatives, risk metrics, portfolio optimization, Monte Carlo, statistics, crypto/DeFi, macro/FX, time value of money. 1,000 free calls/day — no signup required.",
            homepage: "https://quantoracle.dev",
            repository: "https://github.com/QuantOracledev/quantoracle",
            documentation: "https://api.quantoracle.dev/docs",
            license: "MIT",
            keywords: ["finance", "quantitative", "options", "derivatives", "risk", "portfolio", "statistics", "crypto", "defi", "macro", "fx", "backtesting", "deterministic", "calculator"],
            tools: toolDefs.map((t) => ({

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata presents this as deterministic local quantitative-finance computation, but the implementation dynamically fetches an OpenAPI spec from a remote service and proxies tool calls to that backend. This creates a trust-boundary mismatch: users and agents may disclose inputs to a third party, receive behavior that can change without local code changes, and encounter metering/payment behavior not apparent from the stated skill function.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @hono/node-server==1.19.12 — 2 advisory(ies): CVE-2026-39406 (@hono/node-server: Middleware bypass via repeated slashes in serveStatic); GHSA-frvp-7c67-39w9 (Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encode)

Low
Category
Supply Chain
Confidence
85% confidence
Finding

The lockfile includes @hono/node-server 1.19.12, which is flagged for serveStatic-related middleware bypass/path traversal issues. Even though this package is transitive via the MCP SDK and the vulnerable code paths may not be exercised by this skill, dependency-level exposure is real and could become exploitable if static file serving or affected path handling is enabled.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==2.2.2 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
76% confidence
Finding

body-parser 2.2.2 is present as a transitive dependency under the MCP SDK and is reported vulnerable to denial of service when invalid limit values are handled incorrectly. This is a genuine dependency risk, though its exploitability depends on whether the affected parser configuration is used at runtime.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==1.20.4 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
83% confidence
Finding

The top-level express 4.22.1 dependency pulls in body-parser 1.20.4, which is separately flagged for the same denial-of-service issue. Because this is part of the direct web stack of the skill, it is more likely to be reachable than a purely unused dev dependency, although the advisory remains low impact.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: esbuild==0.27.7 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.14.2 — 3 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-8723 (qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/u); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
82% confidence
Finding

qs 6.14.2 is present and reported with denial-of-service and parser limit bypass issues. Because qs is commonly used in Express request query/body parsing, malformed attacker-supplied input could trigger excessive resource use or bypass array parsing limits in exposed HTTP endpoints.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 44)May include surrounding context.

json
"license": "MIT",
  "author": "QuantOracle",
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.12.1",
    "express": "^4.21.0"
  },
  "devDependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 45)May include surrounding context.

json
"author": "QuantOracle",
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.12.1",
    "express": "^4.21.0"
  },
  "devDependencies": {
    "@types/express": "^5.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 48)May include surrounding context.

json
"express": "^4.21.0"
  },
  "devDependencies": {
    "@types/express": "^5.0.0",
    "@types/node": "^22.0.0",
    "tsx": "^4.19.0",
    "typescript": "^5.7.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 49)May include surrounding context.

json
},
  "devDependencies": {
    "@types/express": "^5.0.0",
    "@types/node": "^22.0.0",
    "tsx": "^4.19.0",
    "typescript": "^5.7.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 50)May include surrounding context.

json
"devDependencies": {
    "@types/express": "^5.0.0",
    "@types/node": "^22.0.0",
    "tsx": "^4.19.0",
    "typescript": "^5.7.0"
  },
  "files": [

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 51)May include surrounding context.

json
"@types/express": "^5.0.0",
    "@types/node": "^22.0.0",
    "tsx": "^4.19.0",
    "typescript": "^5.7.0"
  },
  "files": [
    "dist",

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:7

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/index.ts:14