T08 · Insecure Dependencies
- Location
SKILL.md:77- Finding
Unpinned npm Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Doorstep is a coherent real-world errand skill, but it needs Review because its default setup runs an unpinned local npm bridge and it under-warns users about sensitive task data shared with Doorstep and human taskers.
Before installing, prefer the HTTP/OAuth connection if your client supports it, or pin and verify the npm bridge package before using npx. Treat Doorstep requests as information shared with both a service operator and human taskers: provide only necessary addresses, contact details, and sensitive notes, and keep manual quote approval enabled unless you set a clear budget limit.
SKILL.md:77Unpinned npm Package Is Automatically Downloaded and Executed
The skill encourages users to submit real-world pickup and delivery requests that inherently involve addresses, routines, and potentially health-related or other sensitive details, but it does not warn that this information will be shared with a human tasker. In this context, omission of a privacy warning increases the risk of oversharing personal, location, and special-category data to a third party operating in the physical world.
The README instructs users to run the MCP server via npx without pinning a specific package version, which means future installs may fetch whatever code is currently published under that package name. If the package is compromised, updated maliciously, or a dependency is hijacked, users could execute attacker-controlled code locally when setting up the skill.
This skill facilitates real-world errands that inherently require sharing sensitive personal data such as addresses, phone numbers, delivery details, and potentially purchase contents with a third-party service and human taskers. The description and onboarding text do not provide a clear upfront privacy warning, which can cause users to disclose sensitive information without informed consent.
The skill instructs users to run the MCP bridge via npx -y doorstep without pinning a specific package version. This creates a supply-chain risk because a future compromised or malicious release on the package registry could be fetched and executed automatically at runtime. The risk is elevated by the use of -y, which suppresses prompts and encourages unattended execution.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Alternatively, register via the REST API:
curl -X POST https://trydoorstep.app/api/register \
-H "Content-Type: application/json" \
-d '{"email": "user@example.com", "password": "securepass", "name": "Alice"}'
The configuration example uses npx to execute the doorstep package without a pinned version, allowing whatever the latest registry version is at execution time to run. If the upstream package is compromised, typosquatted, or unexpectedly changed, the agent environment could execute unreviewed code with access to the Doorstep API key.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Safety Rules
- **Quote approval is required by default.** When a quote comes back, always present the plan, pricing, and estimated total to the user and ask for their explicit approval before proceeding. Only call `approve_task` after the user confirms.
- The user may override this by instructing you to auto-approve tasks (e.g. "just handle it", "approve anything under $30"). Follow their instructions, but never auto-approve unless they have explicitly told you to.
- Always present the price in dollars, not cents (divide `estimated_total_cents` by 100).
- If `get_account` shows no payment method, direct the user to the `billing_url` before attempting to create a task.
- If `get_account` shows no emergency contact (`has_emergency_contact: false`), prompt the user for a phone number and call `update_settings` to set it. Doers need this to reach the requester if the agent goes offline.
No suspicious patterns detected.