Rp1
- Category
- MCP Rug Pull
- Confidence
- 65% confidence
- Finding
uvx/uv tool run commands without ==version create a rug-pull risk.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This setup skill is coherent and purpose-aligned, but users should be aware it installs search tooling and modifies local agent configuration.
Install only if you want this project or agent connected to Open Agent Search. Review the MCP config changes before applying them, prefer project scope, avoid optional HTTP hosting unless you need it, and consider pinning or separately verifying the `skills` installer package before running the `npx --yes skills add` command.
uvx/uv tool run commands without ==version create a rug-pull risk.
The skill instructs use of npx --yes skills without pinning a specific package version or verifying integrity. Because npx resolves and executes code from the package registry at runtime, a compromised latest release, typo-squatted dependency, or unexpected upstream change could cause arbitrary code execution on the user's machine during setup.
The manifest suggests activation via the general instruction "Use $open-agent-search-setup to connect Open Agent Search in this project," but does not define when this skill should or should not be invoked. It provides no negative examples or scope constraints, which can lead to unintended activation whenever a user mentions connecting search tools in a project.
No suspicious patterns detected.