Back to skill

Security audit

QuantOracle

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its finance-calculator purpose, but its setup runs an unpinned npm MCP server and can use wallet-based payments, so users should review the install path before enabling it.

Install only if you are comfortable running the QuantOracle MCP npm package from npm or using the hosted MCP endpoint. Prefer a pinned reviewed version, restrict the MCP server's filesystem and environment access, and do not provide an x402 wallet unless you intend to allow paid composite calls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:55
Finding

Unpinned npm Package Is Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:44, README.md:39, README.md:45, and README.md:55
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:42-45:

markdown
## Install

```bash
npx quantoracle-mcp
text

`README.md:36-46`:

```markdown
## Install

```bash
npx quantoracle-mcp

Or install globally:

bash
npm install -g quantoracle-mcp
quantoracle-mcp
text

`README.md:49-57`:

```json
{
  "mcpServers": {
    "quantoracle": {
      "command": "npx",
      "args": ["-y", "quantoracle-mcp"]
    }
  }
}

Technical Analysis

The documented installation and MCP configuration resolve quantoracle-mcp without specifying an exact version or package integrity hash. Consequently, npm retrieves whichever release the registry currently associates with the package's default distribution tag.

The MCP configuration is particularly sensitive because npx -y automatically approves installation and execution without interactive confirmation. The downloaded package executes with the privileges and environment of the MCP host process.

This project contains only documentation and a configuration schema; it does not include the source of the npm package. Therefore, the package's filesystem access, network activity, wallet handling, environment-variable access, and payment behavior cannot be independently verified from the audited artifact.

This is a supply-chain weakness rather than evidence that the current npm package is malicious. Exploitation requires the package, its publisher account, the registry resolution process, or another relevant supply-chain component to be compromised.

Attack Path

  1. An attacker compromises the npm publisher account, package, or another part of the package publication pipeline.
  2. The attacker publishes a malicious version under the `quantor ...[truncated 1423 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm package to a reviewed exact version in every command and MCP configuration, for example:

    json
    {
      "command": "npx",
      "args": ["--no-install", "quantoracle-mcp@2.4.1"]
    }
    

    The exact version must first be installed through a controlled dependency installation process.

  2. Manage the package as a local project dependency rather than resolving the registry's latest release whenever the MCP server starts:

    bash
    npm install --save-exact quantoracle-mcp@2.4.1
    
  3. Commit and enforce a lockfile containing npm integrity metadata. Use npm ci in automated deployments so dependency versions cannot drift silently.

  4. Configure the MCP client to invoke the pinned local executable from node_modules/.bin rather than permitting npx to download missing packages automatically.

  5. Remove the unattended -y installation behavior from long-lived MCP configurations. Fail closed if the reviewed package version is unavailable.

  6. Publish or vendor the relevant MCP transport source with the Skill so reviewers can verify network, wallet, filesystem, and payment behavior.

  7. Run the MCP server under a dedicated least-privileged account or sandbox. Restrict filesystem access, outbound network destinations, environment variables, and wallet capabilities to the minimum required.

  8. Establish an upgrade process that reviews source changes, package provenance, signatures where available, dependency changes, and integrity values before changing the pinned version.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx quantoracle-mcp without a pinned version allows whatever package version is current on npm at execution time to be fetched and run. In an MCP context, that creates a supply-chain risk: a compromised publisher account, malicious update, or dependency hijack could cause arbitrary code execution on the user's machine when they follow the README setup instructions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 113)May include surrounding context.

md
## Resources

- **Browser calculators:** https://quantoracle.dev (12 free calculators)
- **Full API documentation:** https://api.quantoracle.dev/openapi.json
- **Endpoint catalog:** https://api.quantoracle.dev/tools
- **Source repository:** https://github.com/QuantOracledev/quantoracle
- **x402 protocol:** https://x402.org

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 114)May include surrounding context.

md
## Resources

- **Browser calculators:** https://quantoracle.dev (12 free calculators)
- **Full API documentation:** https://api.quantoracle.dev/openapi.json
- **Endpoint catalog:** https://api.quantoracle.dev/tools
- **Source repository:** https://github.com/QuantOracledev/quantoracle
- **x402 protocol:** https://x402.org

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Using npx quantoracle-mcp without a pinned version allows installation of whatever package version is current at execution time, which creates a supply-chain risk. If the package is compromised, unpublished/replaced, or a malicious version is published, users may execute unintended code during install/startup.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The phrase "Ask the agent to use QuantOracle tools for any quantitative finance calculation" does not define clear trigger boundaries or exclusions. Because it covers "any" quant finance calculation without negative examples or scope constraints, it risks unintended invocation on broad finance discussions or routine analysis requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.