Back to skill

Security audit

MCP协议配置

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a setup guide for MCP tools, but it asks users to run unverified remote and unpinned package commands while handling API keys and user data.

Review this before installing. Prefer pinned package versions, avoid curl-to-shell installers, verify package provenance, store API keys with restrictive permissions or environment-managed secrets, and avoid sending sensitive images, prompts, or internal data through the configured MCP tools unless you trust the provider and package chain.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:20
Finding

Unverified Remote Installer Executed Directly by the Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

Technical Analysis

The installation instructions download a remotely hosted shell script and immediately pipe it into sh. The effective code is not contained in the reviewed Skill and can change after publication. No fixed release, cryptographic checksum, signature verification, or separate inspection step is provided.

The uvx prerequisite is relevant to the documented MCP configuration, but executing mutable network content directly is not the minimum-risk installation method. The downloaded script receives all permissions held by the user running the command. Trust in HTTPS does not address compromise of the hosting service, publisher infrastructure, or installer itself.

Attack Path

  1. An attacker compromises the installer endpoint, its publishing process, or another component in the delivery trust chain.
  2. The attacker replaces or modifies the response from https://astral.sh/uv/install.sh.
  3. A user follows the Skill instructions and runs the documented command.
  4. curl retrieves the attacker-controlled response and passes it directly to sh.
  5. The payload executes immediately with the invoking user's privileges, without an opportunity for verification or review.

Impact Assessment

Successful exploitation permits arbitrary command execution with the invoking user's privileges. The payload could read or modify user-accessible files, steal credentials and configuration data, install additional software, or alter shell configuration. The instruction does not explicitly invoke administrative elevation, so system-wide privileges are not inherently obtained; the scope is limited to the user's existing permissions unless the user independently runs it as a privileged account.

Remediation
View remediation

Remediation Suggestions

  • Remove the curl | sh installation pattern.
  • Prefer an official operating-system package manager or another installation channel that supports version pinning and integrity verification.
  • If a standalone artifact is necessary, specify an exact release version and download it to a local file.
  • Verify the artifact against a publisher-provided cryptographic signature or pinned checksum before execution.
  • Execute the verified installer as a separate command so users can inspect it first.
  • Document that installation should occur as an unprivileged user and should not be run with sudo unless a narrowly defined operation explicitly requires it.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Packages Are Installed and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13-104
Vulnerability Type: Insecure third-party dependency execution
Risk Level: Medium

Vulnerable Code:

bash
npm install -g clawhub
json
{
  "mcpServers": {
    "MiniMax": {
      "type": "stdio",
      "command": "uvx",
      "args": ["minimax-coding-plan-mcp"],
      "env": {
        "MINIMAX_API_KEY": "你的API密钥",
        "MINIMAX_MCP_BASE_PATH": "/tmp/mcporter-output",
        "MINIMAX_API_HOST": "https://api.minimaxi.com"
      }
    }
  }
}
bash
npx mcporter --config ~/.config/mcporter/mcporter.json list
bash
npx mcporter --config ~/.config/mcporter/mcporter.json call MiniMax.understand_image \
  "prompt: 描述图片内容" \
  "image_source: /path/to/image.jpg"
bash
npx mcporter --config ~/.config/mcporter/mcporter.json call MiniMax.web_search \
  "query: 搜索内容"
bash
npx mcporter list <服务器名> --schema

Technical Analysis

The instructions globally install clawhub without an exact version and use npx and uvx to execute packages whose versions and integrity are not pinned. Package resolution can therefore select releases published after this Skill was audited. A compromised publisher account, malicious later release, or registry-level supply-chain incident could cause arbitrary package code to execute locally.

There is also a documentation mismatch: the section is titled as installation of mcporter, while the command globally installs clawhub. The relationship between those package names is not established by the reviewed files. This ambiguity makes it harder for users to verify that the installed package is necessary and authentic.

The configured MCP package is launched with MINIMAX_API_KEY in its environment. Consequently, the trust placed in the dynamically resolved package extends to that API credential. Commands involving image analysis also prov ...[truncated 1285 chars]

Remediation
View remediation

Remediation Suggestions

  • Verify and correct the mismatch between the stated mcporter installation goal and the clawhub package being globally installed.
  • Pin every npm and Python package to a reviewed, exact version rather than resolving the latest available release.
  • Use lockfiles and package-manager integrity metadata where supported.
  • Avoid global installation unless it is functionally necessary; prefer a project-local, isolated environment.
  • Configure npx so it cannot silently fetch an absent package, or invoke a previously installed and verified local binary.
  • Invoke uvx with a pinned package version and use an isolated cache or environment with controlled provenance.
  • Verify package ownership, official documentation, release signatures, hashes, and registry provenance before execution.
  • Scope the API key to the minimum necessary permissions, rotate it if package integrity is questioned, and avoid exposing unrelated secrets to the MCP child process.
  • Clearly document which local files and network services each MCP server can access before users enable it.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping curl output into sh chains network retrieval directly into shell execution, eliminating any pause for validation. If the remote content is malicious or tampered with, arbitrary commands will run immediately on the user's system.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

bash
which uvx
# 如果没有:
curl -LsSf https://astral.sh/uv/install.sh | sh

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

2.1 创建配置文件

bash
mkdir -p ~/.config/mcporter

2.2 MiniMax MCP 配置示例

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The configuration example includes an API key field but provides no guidance on secure credential handling. Users may hardcode real secrets into plaintext files, commit them to repositories, or expose them through weak file permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation instructs users to run npx mcporter without pinning an exact package version. This can cause different code to be fetched and executed over time, increasing supply-chain risk if a newer package version is compromised or introduces unsafe behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill shows how to send images and search queries through an external MCP server and upstream API, but it omits any warning that user data will leave the local environment. This can lead to accidental disclosure of sensitive images, prompts, or internal information to third-party services.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx mcporter without a pinned version means the invoked package may vary by install time and environment. In a tool-execution workflow, this exposes users to unreviewed upstream changes and package takeover scenarios.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command example relies on npx to resolve the latest available mcporter, which is a reproducibility and supply-chain security weakness. Because the skill is about connecting external MCP tooling, executing an unexpected package version could directly affect local files, credentials, or outbound requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Schema-inspection guidance still uses unpinned npx mcporter, preserving the same package substitution risk as the other examples. Even read-like commands execute package code locally, so this is not harmless from a security perspective.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill documentation is presented in Chinese, with no indication that language selection is optional or that the skill is intentionally region-specific. This can violate a language/locale policy when a specific language is imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The skill instructs users to fetch and execute a remote install script directly from the network. This bypasses meaningful review and makes users trust both the remote host and the transport path at execution time, creating a classic supply-chain compromise vector.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

bash
which uvx
# 如果没有:
curl -LsSf https://astral.sh/uv/install.sh | sh

Static analysis

No suspicious patterns detected.