Back to skill

Security audit

fulcra-get-started

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent Fulcra onboarding guidance, but it asks agents to run an unpinned external CLI while handling sensitive personal data and persistent credentials.

Review before installing. The skill appears intended for legitimate Fulcra onboarding, not deception, but only use it in an environment where running the Fulcra CLI is acceptable. Prefer a pinned, reviewed CLI version, protect the Fulcra credentials file, avoid unrelated secrets in the environment, and confirm before uploading local files or creating remote schemas.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/fulcra-cli.md:9
Finding

Unpinned Third-Party Package Is Dynamically Retrieved and Executed

Content
View full analysis
--poll-timeout=5 ``` ### Technical Analysis The Skill instructs the Agent to use `uv tool run fulcra-api` without specifying a reviewed package version, artifact hash, lock file, or trusted package-index configuration. This command can dynamically resolve, download, install, and execute the package available from the configured Python package source at invocation time. Consequently, the code executed by the Skill can change after the Skill itself has been reviewed. A compromised maintainer account, malicious package release, package-index compromise, dependency-confusion condition, or unsafe custom index could cause attacker-controlled code to execute locally. The linked source repository does not ensure that the dynamically resolved package is built from a particular reviewed commit. The project also provides no integrity verification tying the downloaded artifact to that repository. ### Attack Path 1. An attacker compromises the `fulcra-api` distribution, one of its transitive dependencies, its publishing account, or a package source configured in the execution environment. 2. The attacker publishes a malicious version that satisfies the unconstrained package resolution request. 3. A user or Agent follows the Skill instructions and runs `uv tool run fulcra-api`. 4. `uv` retrieves and executes the attacker-controlled package wi ...[truncated 1327 chars]
Remediation
View remediation
' ``` 2. Use a lock file or verified artifact with cryptographic hashes so package content cannot change without an explicit review. 3. Explicitly configure and document the trusted package index. Do not permit fallback to arbitrary or user-controlled indexes when executing the package. 4. Verify that the published artifact corresponds to a reviewed source commit, preferably through signed releases, provenance attestations, and reproducible-build metadata. 5. Review and pin transitive dependencies, not only the top-level `fulcra-api` package. 6. Obtain explicit user approval before the first package download or execution, explaining that third-party code will execute with the user account’s local permissions. 7. Where practical, run the CLI in a restricted environment with: - Minimal filesystem access. - No unrelated secrets in environment variables. - Restricted outbound network access. - A dedicated low-privilege operating-system account. - Narrowly scoped Fulcra authorization. 8. Ensure `~/.config/fulcra/credentials.json` is created with owner-only permissions and avoid exposing its contents through logs, command output, or shared working directories. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/fulcra-cli.md (reported line 37)May include surrounding context.

md
**Network Restrictions:** If the login command immediately fails or prints a raw `<http.client.HTTPResponse object...>` error, your shell likely lacks outbound network access. Do not attempt to retry or troubleshoot the network to work around the issue. Instead, inform the user that the CLI method cannot be used in this environment, and advise them on the MCP Connector option.

Credentials will be persisted on the filesystem to `~/.config/fulcra/credentials.json` and the tool will refresh access tokens as neccessary.


## Usage

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/fulcra-cli.md (reported line 37)May include surrounding context.

md
**Network Restrictions:** If the login command immediately fails or prints a raw `<http.client.HTTPResponse object...>` error, your shell likely lacks outbound network access. Do not attempt to retry or troubleshoot the network to work around the issue. Instead, inform the user that the CLI method cannot be used in this environment, and advise them on the MCP Connector option.

Credentials will be persisted on the filesystem to `~/.config/fulcra/credentials.json` and the tool will refresh access tokens as neccessary.


## Usage

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The documentation repeatedly instructs agents to execute uv tool run fulcra-api without pinning an exact package version. That allows whatever the latest published package is at execution time to be fetched and run, creating a supply-chain risk where a compromised or malicious upstream release could execute arbitrary code in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The unpinned uv tool run fulcra-api invocation means the agent may download and execute a different package version over time. In a skill that is meant to be followed operationally, this creates a realistic remote code execution and supply-chain compromise path if the package or its dependencies are tampered with.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This command continues the same pattern of executing an unpinned external CLI fetched at runtime. Because the skill is instructing agents to authenticate and handle user-linked data, supply-chain compromise here could expose credentials and sensitive user information.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using --help via an unpinned package still requires executing that package, so even seemingly harmless commands inherit the same supply-chain risk. An attacker controlling a later release could run arbitrary code before printing help output.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The example for authentication again depends on an unpinned runtime package fetch. In context, this is more dangerous because the command participates in an auth flow and could steal device codes, tokens, or alter login behavior if the package is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The second auth-step command has the same unpinned execution risk and handles a device code directly. A malicious upstream release could capture the device code, exfiltrate tokens, or trick the user during authentication.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Although this example queries a catalog, it still executes a remotely fetched unpinned package. The main risk remains supply-chain compromise rather than the specific business action shown in the example.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example retrieves health-related step-count records using an unpinned CLI package. In context, the combination of supply-chain risk and access to sensitive personal data increases the potential privacy impact of a malicious package update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The heart-rate example uses the same unpinned runtime package pattern while touching especially sensitive biometric data. A compromised release could exfiltrate or alter medical-style metrics without the user realizing it.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Even this user-info query executes an unpinned external CLI package. While the data sensitivity here may be lower than health metrics, the package still runs with the agent's privileges and may access configuration or credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as a getting-started guide, but it goes beyond orientation into authenticated schema creation and remote file-management operations. That scope expansion can cause agents or new users to perform broad, state-changing actions they did not intend, increasing the chance of accidental data modification or disclosure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Creating custom data types via an unpinned CLI expands risk beyond code execution to integrity of the remote Fulcra environment. A malicious or altered package could create deceptive schemas, corrupt records, or abuse authenticated write access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The catalog base-types example still causes execution of an unpinned package and therefore retains the same supply-chain exposure. The command itself is read-oriented, but the trust boundary violation remains substantial.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example creates a new annotation type using an unpinned external package with authenticated write capability. If the package is compromised, it could silently perform additional writes, alter names/descriptions, or exfiltrate session material.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The boolean annotation creation command repeats the pattern of unaudited runtime package execution during a state-changing action. Because the skill encourages direct operational use, this is not merely theoretical documentation debt but guidance likely to be copied verbatim.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This numeric annotation example combines write access with an unpinned package invocation. A malicious package version could abuse the session to create or manipulate remote objects beyond the visible command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The scale annotation creation example preserves the same supply-chain weakness on a remote write path. In a skill that interfaces with personal data systems, any hidden extra behavior in the fetched package can affect confidentiality, integrity, and auditability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file-store section instructs agents to upload and download files to a remote service without prominent warnings about data transmission, sensitivity, consent, or local-path risks. In this context the platform stores highly personal and agent-generated data, so omission of privacy and transfer safeguards materially increases the risk of unintended disclosure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The file upload command is especially risky because it both fetches an unpinned executable and transmits local content to a remote store. A compromised package could exfiltrate additional local files, alter uploads, or embed hidden data in remote artifacts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Listing remote files with an unpinned package still exposes the agent to arbitrary code execution and potential metadata exfiltration. The immediate business action is lower risk than upload/download, but the supply-chain issue remains valid.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The file stat example invokes an unpinned package against a remote store. A malicious release could use the opportunity to harvest remote file metadata, credentials, or local environment details.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Downloading a remote file through an unpinned CLI is high risk because it combines arbitrary package execution with content transfer into the local environment. A compromised package could overwrite local files, deliver tampered content, or exfiltrate existing data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

A 'get started' skill is justified in explaining primary setup and basic usage, but recommending fallback implementation methods like raw HTTP requests or a separate SDK introduces additional capabilities not necessary for initial setup guidance. This expands the skill into general integration and programmatic access territory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.