Back to skill

Security audit

mcp-domain-intel

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to provide domain lookup tools, but its install instructions automatically run an unpinned npm package and the documentation is inconsistent about package name, tool names, and environment variables.

Review carefully before installing. Prefer a pinned, reviewed package version or a local build from the inspected source, confirm whether the intended package is @vbotholemu/mcp-domain-intel or @blue-trianon/mcp-domain-intel, and use the correct NAUTDEV_BASE_URL setting if you intend to control the API endpoint.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party Package Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:22-23
Vulnerability Type: Unsafe supply-chain dependency execution
Risk Level: Medium

Vulnerable Code

json
"command": "npx",
"args": ["-y", "@vbotholemu/mcp-domain-intel"],

Technical Analysis

The documented MCP configuration invokes npx with the -y option and a package name that has no exact version or integrity constraint. Consequently, following these instructions may cause npm to resolve, download, and execute whichever package release is current at execution time.

The effective executable can therefore change after this source artifact has been reviewed. The -y option further removes the interactive confirmation that might otherwise alert the user to package installation. This creates a supply-chain boundary in which the security of local execution depends on the npm publisher account, registry resolution, and all content included in the subsequently resolved release.

This finding does not establish that the current package is malicious. The risk arises because the instructions permit future, unaudited package content to be downloaded and executed automatically.

Attack Path

  1. An attacker compromises the npm publisher account, publishing workflow, or package distribution channel for @vbotholemu/mcp-domain-intel.
  2. The attacker publishes a malicious package release under the same package identity.
  3. A user copies the configuration from SKILL.md and starts the MCP server.
  4. npx -y resolves and downloads the unpinned package without an interactive installation prompt.
  5. npm executes the package entry point.
  6. The malicious package runs with the operating-system permissions and environment available to the MCP host process.

Impact Assessment

Successful exploitation permits arbitrary code execution with the privileges of the user running the MCP client. Depending on the host environment, the malicious package could access readable files, environment v ...[truncated 369 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the package to a reviewed exact version, for example @vbotholemu/mcp-domain-intel@1.0.0, rather than allowing registry resolution to select a later release.
  • Remove -y where practical so unexpected installation requires explicit user confirmation.
  • Prefer installing dependencies through a committed lockfile and enforce package integrity verification during installation.
  • Build and execute the reviewed local source artifact when reproducibility is required.
  • Run the MCP server under a dedicated, least-privileged account or sandbox with narrowly scoped filesystem, environment-variable, and network access.
  • Establish a release process using protected publisher credentials, multi-factor authentication, provenance attestations, and review of package contents before publication.
  • Keep package identity and configuration consistent across SKILL.md, README.md, and package.json so users do not unintentionally install a different package than the audited artifact.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises concrete domain intelligence functionality, but the provided code does not implement any such behavior. Since the code chunk is just an empty declaration stub, its actual behavior does not match the stated primary purpose. This is a material mismatch because the declared capability is absent rather than merely incomplete in a supporting detail.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares executable/networked behavior via an MCP server and environment variables, but does not define any explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and makes it harder for a host or reviewer to constrain what the skill may access at runtime, especially since it invokes an external package and network API.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill installs/runs an external package through npx using a floating reference (@vbotholemu/mcp-domain-intel) instead of a pinned immutable version. This creates a supply-chain risk: a later malicious or compromised package release could be fetched and executed automatically in environments using the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The helper performs HTTP requests to an external API, and the tool handlers pass user-provided domain names to that service. While the tool descriptions explain the purpose, there is no explicit user-facing warning, comment, or disclosure that input will be sent to a remote endpoint.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 26)May include surrounding context.

json
"author": "Blue-Trianon-Ventures",
  "license": "MIT",
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.12.1",
    "zod": "^3.23.0"
  },
  "devDependencies": {

Unverifiable Dependency: @modelcontextprotocol/sdk has 3 known advisory(ies) (CVE-2026-25536 (@modelcontextprotocol/sdk has cross-client data leak via shared server/transport); CVE-2026-0621 (Anthropic's MCP TypeScript SDK has a ReDoS vulnerability); CVE-2025-66414 (Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protec)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
71% confidence
Finding

The manifest depends on @modelcontextprotocol/sdk with a non-exact version while known advisories exist for that package, making it impossible to verify from this file whether installs will select an affected release. In the context of an MCP server skill that likely handles client/server transport and network-facing interactions, unresolved SDK vulnerabilities could expose cross-client data leakage, ReDoS, or DNS-rebinding-related risks if an affected version is installed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 27)May include surrounding context.

json
"license": "MIT",
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.12.1",
    "zod": "^3.23.0"
  },
  "devDependencies": {
    "typescript": "^5.7.0",

Unverifiable Dependency: zod has 1 known advisory(ies) (CVE-2023-4316 (Zod denial of service vulnerability)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
63% confidence
Finding

zod has a known DoS advisory, and because the dependency is not pinned, this manifest does not let reviewers determine whether deployments will use a patched or vulnerable release. In a domain-intelligence skill that likely validates user-supplied inputs such as domains or query parameters, a vulnerable schema parser could contribute to denial-of-service if maliciously crafted inputs trigger excessive processing.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 30)May include surrounding context.

json
"zod": "^3.23.0"
  },
  "devDependencies": {
    "typescript": "^5.7.0",
    "@types/node": "^22.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 31)May include surrounding context.

json
},
  "devDependencies": {
    "typescript": "^5.7.0",
    "@types/node": "^22.0.0"
  }
}

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:7

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/index.ts:7