Back to skill

Security audit

oVirt MCP Server

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent oVirt/RHV management reference, but it enables high-impact infrastructure administration with under-scoped safety guidance and unpinned third-party server installation instructions.

Review this skill carefully before installing. Use a pinned and verified MCP server release, run it under a restricted account, avoid broad `admin@internal` credentials where possible, store the oVirt password in a protected secret mechanism, and require explicit human confirmation before delete, force, fence, install, export, migration, storage, network, or RBAC-changing operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party MCP Server Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14-25
Vulnerability Type: Unpinned external dependency installation
Risk Level: Medium

bash
### Install

```bash
pip install ovirt-engine-mcp-server

Or from source:

bash
git clone https://github.com/imjoey/ovirt-engine-mcp-server.git
cd ovirt-engine-mcp-server
pip install -e .
text

### Technical Analysis

The Skill directs users to install an external Python package without pinning a version, commit, or package hash. The alternative installation method clones and installs the mutable default branch of an external Git repository. Consequently, the code ultimately installed can change after this Skill has been reviewed.

The external MCP server implementation is not included in the audited project, so its behavior and transitive dependencies could not be verified. Python package installation may execute package build hooks, while the installed MCP server will subsequently run as a local process. If the PyPI package, maintainer account, source repository, or an unpinned transitive dependency is compromised, attacker-controlled code could be delivered through these documented installation procedures.

This finding identifies a supply-chain exposure; the audit found no evidence that the currently referenced package or repository is malicious.

### Attack Path

1. An attacker compromises the referenced PyPI project, its publisher credentials, the source repository, or an unpinned transitive dependency.
2. The attacker publishes a modified release or commits malicious code to the repository's default branch.
3. A user follows the Skill instructions and runs `pip install ovirt-engine-mcp-server` or clones the mutable default branch and runs `pip install -e .`.
4. Attacker-controlled code executes during installation or when `ovirt-engine-mcp` is launched.
5. The malicious process operates with the installing user's local privileges and
...[truncated 957 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the PyPI dependency to a specifically reviewed version, for example:
    bash
    pip install "ovirt-engine-mcp-server==<reviewed-version>"
    
  2. Use package hashes with pip --require-hashes and maintain a reviewed lockfile containing all transitive dependencies.
  3. Replace cloning of the mutable default branch with checkout of a reviewed immutable commit:
    bash
    git clone https://github.com/imjoey/ovirt-engine-mcp-server.git
    cd ovirt-engine-mcp-server
    git checkout <reviewed-commit-hash>
    
  4. Verify release signatures, repository provenance, and package hashes before installation.
  5. Avoid editable installations for production deployment. Build and deploy a reproducible artifact from the reviewed source revision.
  6. Run the MCP server under a dedicated, restricted operating-system account or container with minimal filesystem and network access.
  7. Configure a dedicated least-privilege oVirt service account instead of the documented broad admin@internal account.
  8. Store the oVirt password in a protected secret manager or credential provider rather than persistent plaintext client configuration.
  9. Establish a dependency update process requiring review and security testing before changing pinned versions or commits.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (42)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description advertises extensive create/delete/modify capabilities across VMs, hosts, storage, networks, and RBAC, but does not warn that these operations are destructive and affect production infrastructure. In this context, lack of safety messaging is especially dangerous because the toolset can alter or remove critical virtualized resources and permissions, amplifying the consequences of user misunderstanding or accidental invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Fence actions directly affect host power state and availability, yet the documentation does not warn about immediate service interruption, split-brain risk, or consequences for resident workloads. In a virtualization-management context, presenting restart/start/stop/status together without safety guidance can lead to accidental host shutdowns or restarts with cluster-wide impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Host installation/reinstallation is a high-risk operation that can reconfigure or overwrite system state, but the documentation omits any warning about data loss, credential handling, or downtime. Because this skill manages production virtualization hosts, lack of cautionary guidance materially increases the chance of destructive misuse by an agent or user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README prominently advertises powerful infrastructure-management actions such as VM creation, migration, fencing, storage operations, and RBAC changes, but provides no caution that these actions can be disruptive, destructive, or security-sensitive. In an agent-skill context, this omission increases the chance that an AI agent or operator invokes high-impact tools without explicit confirmation, change-control, or awareness of production consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad terms such as virtual machine, cluster, and host management, which overlap with common infrastructure discussions and can cause unintended skill activation. In a skill that exposes 186 management actions over virtualization infrastructure, accidental invocation can lead to unnecessary credential use, confusing tool routing, or unintended destructive operations if the agent proceeds without strong confirmation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

The Docker example runs an unpinned image tag, which means consumers may execute whatever image is currently associated with that name when they follow the documentation. For an infrastructure-management server that handles privileged oVirt credentials and can perform destructive operations, mutable image references materially increase supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill reference documents deletion actions for affinity groups but provides no warning about the destructive effect, confirmation requirement, or potential impact on system configuration. For markdown files, destructive behaviors that could affect user data or system integrity should be disclosed clearly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The affinity_label_delete entry documents a delete capability but does not warn users that removing a label can change resource scheduling or policy behavior. This omits user-facing disclosure for an operation that can affect system integrity or configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation exposes a destructive cluster_delete capability with no warning about permanence, prerequisites, or likely service impact. In an infrastructure-management skill for oVirt/RHV, this omission increases the chance that an agent or user invokes cluster deletion without understanding that dependent hosts, VMs, storage/network associations, or production workloads may be disrupted or lost.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation exposes a destructive datacenter_delete capability with no warning, confirmation requirement, or guidance about irreversible consequences. In an infrastructure-management skill for oVirt/RHV, deleting a data center can cause major service disruption or cascading loss of associated configuration and resources, so omission of safeguards materially increases the risk of accidental or unsafe use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation exposes a destructive disk deletion operation and a force-delete option without any caution about permanence, attachment/state checks, or confirmation requirements. In an infrastructure-management skill, missing safety guidance increases the chance of accidental destructive actions that can cause irreversible data loss or service disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Disk export is a data-exfiltration-capable operation, yet the documentation does not warn that exported images may contain sensitive system and customer data or that destination export domains must be trusted and access-controlled. In an oVirt/RHV management skill, this omission is more dangerous because the tool directly supports administrative actions over production virtual infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes a destructive administrative action, event_clear_alerts, with no warning, confirmation guidance, or explanation of scope. In an infrastructure-management skill for oVirt/RHV, clearing alerts can erase operational signal, hinder incident response, and cause users or downstream agents to perform state-changing actions without understanding the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation exposes a destructive host removal operation without any caution about workload disruption, possible data/access loss, or prerequisite checks. In an infrastructure-management skill, omission of warnings increases the chance that an agent or operator will invoke the action unsafely and cause avoidable outages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation exposes a destructive network_delete operation with no warning about service impact, dependency checks, or confirmation expectations. In an infrastructure-management skill for oVirt/RHV, deleting a network can disconnect VMs, break host connectivity, or disrupt cluster operations, so omission of safeguards materially increases the chance of harmful misuse or operator error.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The nic_remove documentation describes removing a VM NIC without warning that it may immediately sever guest network access or interrupt production services. Because this skill is intended for direct VM administration, the lack of cautionary guidance can lead an agent or operator to perform service-affecting actions without validating maintenance windows or fallback access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The vnic_profile_delete entry omits warning about downstream dependencies, even though VNIC profiles may be referenced by VM NICs and network configurations. In a virtualization control-plane context, deleting an in-use profile can cause provisioning failures or connectivity issues, making the missing warning a meaningful operational security and availability risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document exposes a destructive quota_delete operation with no warning, confirmation guidance, or mention of consequences such as permanent quota removal or service disruption. In an infrastructure-management skill for oVirt/RHV, undocumented destructive actions increase the chance that an agent or user invokes deletion unsafely, causing accidental administrative damage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file documents destructive identity and access control actions such as deleting a user, but provides no warning about impact, irreversibility, or need for confirmation. For markdown files, safety-relevant behaviors that can affect user data or system integrity should include explicit warnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Deleting roles can immediately change or remove access rights across the system, yet the skill description only lists parameters and omits any cautionary language. This is a missing user warning for a security-sensitive and potentially disruptive operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Assigning or revoking permissions directly changes authorization on resources, which can grant or remove access in ways that affect security posture. The markdown provides no warning to users about these consequences or the need to verify the target principal and resource.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation exposes a destructive operation (storage_delete) with a force option but provides no warning about permanent data loss, dependency impact, or recommended pre-checks. In an infrastructure-management skill for oVirt/RHV, this can lead users or downstream agents to delete active storage domains without understanding the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The storage_detach operation is documented as a simple action without warning that detaching a storage domain can interrupt VM access, break data availability, or affect data center configuration. Because this skill is designed for direct virtualization administration, the lack of caution increases the chance of harmful misuse or accidental outages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents the skill documentation entirely in Chinese and does not offer any language choice or indicate that the locale restriction is intentional for a region-specific use case. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation exposes a destructive template_delete operation, including an optional force flag, without warning about permanence, dependency impacts, or the need for confirmation. In an infrastructure-management skill for oVirt/RHV, this omission increases the chance that an agent or user will trigger irreversible deletion of shared templates that may be used to provision multiple VMs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.