Back to skill

Security audit

Doorstep

Security checks for vulnerabilities and agentic risk

Overview

Doorstep is a coherent real-world errand skill, but it needs Review because its default setup runs an unpinned local npm bridge and it under-warns users about sensitive task data shared with Doorstep and human taskers.

Before installing, prefer the HTTP/OAuth connection if your client supports it, or pin and verify the npm bridge package before using npx. Treat Doorstep requests as information shared with both a service operator and human taskers: provide only necessary addresses, contact details, and sensitive notes, and keep manual quote approval enabled unless you set a clear budget limit.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:77
Finding

Unpinned npm Package Is Automatically Downloaded and Executed

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages users to submit real-world pickup and delivery requests that inherently involve addresses, routines, and potentially health-related or other sensitive details, but it does not warn that this information will be shared with a human tasker. In this context, omission of a privacy warning increases the risk of oversharing personal, location, and special-category data to a third party operating in the physical world.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run the MCP server via npx without pinning a specific package version, which means future installs may fetch whatever code is currently published under that package name. If the package is compromised, updated maliciously, or a dependency is hijacked, users could execute attacker-controlled code locally when setting up the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill facilitates real-world errands that inherently require sharing sensitive personal data such as addresses, phone numbers, delivery details, and potentially purchase contents with a third-party service and human taskers. The description and onboarding text do not provide a clear upfront privacy warning, which can cause users to disclose sensitive information without informed consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users to run the MCP bridge via npx -y doorstep without pinning a specific package version. This creates a supply-chain risk because a future compromised or malicious release on the package registry could be fetched and executed automatically at runtime. The risk is elevated by the use of -y, which suppresses prompts and encourages unattended execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

Alternatively, register via the REST API:

bash
curl -X POST https://trydoorstep.app/api/register \
  -H "Content-Type: application/json" \
  -d '{"email": "user@example.com", "password": "securepass", "name": "Alice"}'

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The configuration example uses npx to execute the doorstep package without a pinned version, allowing whatever the latest registry version is at execution time to run. If the upstream package is compromised, typosquatted, or unexpectedly changed, the agent environment could execute unreviewed code with access to the Doorstep API key.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 287)May include surrounding context.

md
## Safety Rules

- **Quote approval is required by default.** When a quote comes back, always present the plan, pricing, and estimated total to the user and ask for their explicit approval before proceeding. Only call `approve_task` after the user confirms.
- The user may override this by instructing you to auto-approve tasks (e.g. "just handle it", "approve anything under $30"). Follow their instructions, but never auto-approve unless they have explicitly told you to.
- Always present the price in dollars, not cents (divide `estimated_total_cents` by 100).
- If `get_account` shows no payment method, direct the user to the `billing_url` before attempting to create a task.
- If `get_account` shows no emergency contact (`has_emergency_contact: false`), prompt the user for a phone number and call `update_settings` to set it. Doers need this to reach the requester if the agent goes offline.

Static analysis

No suspicious patterns detected.