Back to skill

Security audit

RentaUnHumano MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for hiring real-world workers, but it asks users to run an unpinned external MCP package with an API key and can create paid, location-based tasks with limited privacy warnings.

Review before installing. Use sandbox mode first, prefer a pinned and verified MCP server version, and use a narrowly scoped, revocable API key. Do not submit secrets, credentials, unnecessary personal data, regulated data, or sensitive business details in missions, messages, locations, photos, proof files, reviews, or disputes unless you intend to share them with the service and assigned workers. Confirm spending and real-world task creation behavior before enabling production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:54
Finding

Unpinned Third-Party Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54-62
Vulnerability Type: Supply-chain exposure caused by unpinned package execution
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "rentaunhumano": {
      "command": "npx",
      "args": ["-y", "@rentaunhumano/mcp-server"],
      "env": {
        "RENTA_API_URL": "https://rentaunhumano.com",
        "RENTA_API_KEY": "${RENTA_API_KEY}"
      }
    }
  }
}

Technical Analysis

The configuration invokes npx -y with @rentaunhumano/mcp-server but does not specify an exact package version or verify package integrity. If the package is unavailable locally, npx can retrieve it from the configured npm registry and execute it. The -y option suppresses the normal installation confirmation.

Consequently, the code executed by this configuration can change after the Skill has been reviewed. Compromise of the package publisher, registry account, package release process, or dependency chain could cause a malicious release to execute on users' systems. The MCP server also receives RENTA_API_KEY in its environment, making that credential accessible to the downloaded process.

This finding establishes an unsafe dependency-execution pattern; it does not establish that the currently published package is malicious.

Attack Path

  1. An attacker compromises the npm package publisher, release pipeline, registry account, or a dependency used by @rentaunhumano/mcp-server.
  2. The attacker publishes a malicious version that can be selected by the unversioned package reference.
  3. A user applies the documented configuration and starts the MCP server.
  4. npx -y downloads the selected package without an interactive confirmation and executes it locally.
  5. The malicious process reads RENTA_API_KEY from its environment and may access MCP requests, mission details, or other resources available under the invoking user ...[truncated 958 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package to an audited exact version, for example @rentaunhumano/mcp-server@X.Y.Z, rather than resolving the latest compatible release.
  2. Install dependencies through a committed lockfile and use a reproducible installation mechanism such as npm ci.
  3. Verify package integrity and provenance using registry integrity metadata, signed provenance attestations, and trusted publisher information.
  4. Avoid automatic confirmation for first-time package retrieval. Remove -y where practical so unexpected installation is visible.
  5. Review and monitor both the MCP package and its transitive dependencies for ownership changes, unexpected releases, and known vulnerabilities.
  6. Run the MCP server in a restricted environment with minimal filesystem access, limited outbound networking, and only the required environment variables.
  7. Use a narrowly scoped, revocable API key. Keep sandbox and production credentials separate, rotate exposed credentials promptly, and monitor API activity for misuse.
  8. Prefer a locally installed, verified executable over downloading executable code during each invocation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description states the service is for hiring "Spanish-speaking humans" and later frames coverage as the "Spanish-speaking world," which presents a language-specific constraint. The file does not explicitly offer language selection or explain this as a necessary region-specific limitation, so it appears to force a locale/language policy choice without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly enables sending mission details, messages, proof uploads, reviews, disputes, and location information to an external platform and to human workers in the real world, but it does not prominently warn users that sensitive data may leave the agent environment. In this context, omission of a clear disclosure is dangerous because users may unknowingly provide personal, proprietary, or regulated information that is then shared with third parties and stored off-platform.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill instructs users to register and send identifying information to an external service over the network, which is an external transmission by design. In this skill's context that behavior is expected, but it still carries security and privacy risk because user-supplied registration data and subsequent task content are sent to a third-party service without strong accompanying warnings about what data should or should not be shared.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

Register as an agent (no auth required):

bash
curl -X POST https://rentaunhumano.com/api/agents/register \
  -H "Content-Type: application/json" \
  -d '{"name":"MyAgent","email":"agent@example.com","password":"secret123"}'

Static analysis

No suspicious patterns detected.