Back to skill

Security audit

Origin Pro MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Origin Pro automation tool, but it exposes powerful script execution and file-changing operations without enough scoping or safeguards.

Review before installing. Use this only with trusted prompts and trusted data, keep backups of Origin projects, avoid or disable run_labtalk unless you explicitly need it, verify export paths before execution, and prefer running it against disposable projects or a constrained output directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
src/origin_pro_mcp/tools/labtalk.py:4
Finding

Unrestricted LabTalk Interpreter Exposed as an MCP Tool

Content
View full analysis
str: """Execute a LabTalk script in Origin Pro. Use this for any Origin operation not covered by other tools. LabTalk is Origin's built-in scripting language. Args: script: LabTalk script to execute Returns: Success/failure message """ success = execute_labtalk(script) return f"Executed {'successfully' if success else 'with errors'}: {script}" ``` The tool forwards its argument to the following execution sink: ```python def execute_labtalk(script: str) -> bool: o = get_origin() return o.Execute(script) ``` The agent configuration also permits implicit invocation: ```yaml policy: allow_implicit_invocation: true ``` ### Technical Analysis The `run_labtalk` MCP tool accepts an arbitrary string and forwards it unchanged to Origin Pro's LabTalk interpreter. There is no command allowlist, syntax validation, restricted execution mode, authorization check, or confirmation step. This is particularly significant in an AI-agent context because tool arguments can be derived from untrusted prompts, imported documents, or other attacker-controlled content. Allowing implicit invocation increases the possibility that the interpreter could be reached without the user explicitly selecting the advanced scripting feature. The stdio transport limits direct network exposure, but it does not protect against prompt-driven misuse by an authorized local MCP client. ### Attack Path 1. A user or untrusted data source supplies instructions that influence the connected AI agent. 2. The agent selects `run_labtalk`, potentially through implicit skill invo ...[truncated 902 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/origin_pro_mcp/tools/graph.py:91
Finding

LabTalk Injection Through Unescaped MCP Tool Parameters

Content
View full analysis
0: data_ref = f"[{data_book}]{data_sheet}!({x_col},{y_col},{y_error_col})" execute_labtalk(f"plotxy iy:={data_ref} plot:={ptype} ogl:=[{name}]Layer1;") if title: execute_labtalk(f'label -n title -s "{title}"; title.x = 50; title.y = 95;') ``` Additional graph parameters are similarly interpolated: ```python execute_labtalk(f"win -a {graph_name};") if x_label: execute_labtalk(f'xb.text$ = "{x_label}";') if y_label: execute_labtalk(f'yl.text$ = "{y_label}";') if title: execute_labtalk(f'label -n title -s "{title}"; title.x = 50; title.y = 95;') ``` Worksheet names and column labels are not escaped: ```python name = o.CreatePage(2, book_name, "origin") if sheet_name != "Sheet1": execute_labtalk(f'page.active$ = "Sheet1"; wks.name$ = "{sheet_name}";') ``` ```python if column_names: names = [n.strip() for n in column_names.split(",")] execute_labtalk(f'win -a {book_name};') for i, name in enumerate(names): execute_labtalk(f'wks.col{i+1}.lname$ = "{name}";') ``` The fitting function is documented as a fixed set of built-in values but is not actually allowlisted: ```python sheet_ref = f"[{data_book}]{data_sheet}" execute_labtalk(f"win -a {data_book};") execute_labtalk(f"{sheet_ref}!col({x_col}).type = 4;") execute_labtalk(f"{sheet_ref}!col({y_col}).type = 1;") ``` ```python execute_labtalk(f"nlbegin iy:={data_ref} func:={function};") execute_labtalk("nlfit; ...[truncated 2684 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/origin_pro_mcp/tools/graph.py:215
Finding

Caller-Controlled Export Path Can Delete Existing Files Before Export Succeeds

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (24)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/SECURITY.md (reported line 9)May include surrounding context.

md
Before publishing a fork or derivative package, check for:

- API keys, access tokens, passwords, and bearer tokens
- local connector configuration
- absolute paths containing user names
- third-party integration settings

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/SECURITY.md (reported line 29)May include surrounding context.

md
发布 fork 或衍生包前,请检查:

- API key、access token、password、bearer token
- 本地连接器配置
- 带用户名的绝对路径
- 第三方集成配置

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

new_project() immediately calls o.NewProject(), and the docstring states this closes the current project without saving. In an MCP tool context, this creates a destructive action that can be triggered by an agent or user without confirmation, pre-save checks, or backup behavior, making accidental data loss highly plausible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README prominently describes capabilities that can create, load, save, import, and export Origin projects and files, but it does not clearly warn that these actions may overwrite existing projects, worksheets, or output files. In an AI-agent context, missing safety guidance increases the chance of unintended destructive actions because an automated agent may perform file-modifying operations without prompting for confirmation or using isolated output paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool list exposes run_labtalk without an explicit warning that it can execute arbitrary LabTalk commands inside Origin, which may alter projects, files, or invoke dangerous automation behaviors. In this skill's context, the risk is elevated because the package is specifically designed for AI-driven remote control of Origin Pro, so an LLM or user prompt could route untrusted instructions into a powerful command-execution surface.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill exposes operational setup and execution steps that rely on shell commands, package installation, and local server registration, but it does not declare any explicit tool scope such as allowed-tools or permissions. In a skill that automates a desktop application and includes command execution paths, this omission weakens least-privilege controls and can let an agent invoke broader capabilities than users or reviewers expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This function exposes direct LabTalk script execution to the rest of the skill with no validation, restriction, or user confirmation. In the context of an MCP skill designed to automate Origin Pro, this creates a powerful script-injection surface: if untrusted user input is passed into this wrapper, Origin commands could modify projects, access files, run external operations supported by LabTalk, or perform destructive actions without meaningful disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The export_graph tool accepts a user-controlled file path, creates parent directories, and deletes any existing file at that path before export. In an MCP/agent setting, this gives the caller arbitrary write and delete capability on the host filesystem, which exceeds the minimum needed for graph export and can overwrite or remove sensitive local files if the agent is induced to use attacker-chosen paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function silently creates directories and overwrites or deletes existing files without any confirmation or safety interlock. In agent-driven use, a prompt-injected or mistaken request can therefore cause destructive filesystem changes with no user awareness, increasing the chance of data loss or abuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file builds LabTalk commands by interpolating untrusted workbook names, sheet names, and column names directly into command strings. An attacker who controls these identifiers can break out of the quoted context or inject additional LabTalk statements, leading to arbitrary command execution inside the Origin automation environment and unintended modification of projects or files.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_connection.py (reported line 8)May include surrounding context.

python
pytestmark = pytest.mark.origin

def test_origin_connection():
    result = subprocess.run(
        [sys.executable, "-c",
         "import win32com.client; o = win32com.client.Dispatch('Origin.ApplicationSI'); print('OK')"],
        capture_output=True, text=True, timeout=30

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a manifest file, so vague-trigger review applies. The keyword list contains very broad activation terms such as "origin" and "automation" without any stated scope, exclusions, or negative examples, which could contribute to overly broad matching or unintended invocation in systems that use manifest metadata for routing.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: mcp has 12 known advisory(ies) (CVE-2025-53366 (MCP Python SDK vulnerability in the FastMCP Server causes validation error, lead); CVE-2025-66416 (Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection); CVE-2026-52870 (MCP Python SDK: Experimental task handlers allow any client to access and cancel) +9 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

The manifest allows any mcp version >=1.0.0, while the dependency family has multiple known advisories. Because the version is not constrained to a known-safe range, installs may resolve to vulnerable releases depending on environment, mirror state, or lockfile absence; in an MCP server, this is more concerning because the package is network-facing and processes protocol requests.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pywin32 has 2 known advisory(ies) (CVE-2021-32559 (Integer overflow in pywin32); CVE-2021-32559 (An integer overflow exists in pywin32 prior to version b301 when adding an acces)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
78% confidence
Finding

The manifest specifies pywin32>=306 without pinning or excluding vulnerable builds, leaving uncertainty about whether an affected release could be installed. While pywin32 is a local Windows integration dependency rather than the primary network surface, it still interfaces with privileged OS and COM components, so unresolved vulnerable versions increase risk.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: Pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The manifest permits any Pillow version >=10.0.0, but Pillow has a history of image parsing and resource consumption issues. In a skill that exports and potentially processes figures/images, installing an unreviewed vulnerable Pillow build could expose the server or client environment to malformed-image attacks or denial of service.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency specifier mcp>=1.0.0 is unpinned, so installs may resolve to different versions over time, including versions with newly introduced vulnerabilities or breaking security changes. Because this skill exposes automation through an MCP server component, supply-chain drift in the MCP package is more sensitive than in a purely local utility.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
mcp>=1.0.0
pywin32>=306
Pillow>=10.0.0

Unverifiable Dependency: mcp has 12 known advisory(ies) (CVE-2025-53366 (MCP Python SDK vulnerability in the FastMCP Server causes validation error, lead); CVE-2025-66416 (Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection); CVE-2026-52870 (MCP Python SDK: Experimental task handlers allow any client to access and cancel) +9 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The manifest does not pin mcp, and the package has multiple known advisories, so consumers cannot verify whether the resolved version is affected. This is particularly concerning because the skill depends on an MCP server stack, making vulnerabilities in mcp directly relevant to network-facing control and agent-tool interactions.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

pywin32>=306 allows any newer release to be installed without review, which weakens reproducibility and creates supply-chain risk. In this skill, pywin32 is especially relevant because it bridges into Windows COM/automation, so a compromised or vulnerable package could affect a high-privilege local integration surface.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
mcp>=1.0.0
pywin32>=306
Pillow>=10.0.0

Unverifiable Dependency: pywin32 has 2 known advisory(ies) (CVE-2021-32559 (Integer overflow in pywin32); CVE-2021-32559 (An integer overflow exists in pywin32 prior to version b301 when adding an acces)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

pywin32 has known advisories and the unpinned requirement prevents verifying whether installations will avoid affected versions. Given this package interfaces closely with Windows internals, a vulnerable version could have disproportionate consequences on the host running the Origin automation skill.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Pillow>=10.0.0 is not pinned to a specific release, so the installed version may vary and could include vulnerable builds or unreviewed changes. Since this skill mentions figure export and image handling, Pillow may process untrusted image content, increasing the importance of predictable patched versions.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
mcp>=1.0.0
pywin32>=306
Pillow>=10.0.0

Unverifiable Dependency: Pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

Pillow has a history of serious issues including resource exhaustion and potential code-execution-related flaws, and the unpinned requirement means affected versions may be installed unknowingly. Because this skill performs figure export and likely image manipulation, the library is plausibly exercised on attacker-controlled or externally sourced files, raising practical risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code exposes multiple MCP tools that directly modify graph state and worksheet metadata via execute_labtalk, including plot styling, axis labels/ranges, legend content, and font settings. Although these edits are the tool's purpose, there is no visible user disclosure in docstrings or code strings that the operations will mutate the active Origin project and may overwrite existing styling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The function writes user-provided data into an Origin worksheet and may rename columns, which changes existing workbook contents. Although the docstring says 'Write data to an Origin worksheet,' it does not provide an explicit warning or disclosure that the operation alters workbook data and metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code reads a user-specified local file and then creates and populates a workbook, which modifies application state and imports external data. While the docstring describes the function's purpose, there is no explicit user-facing warning, confirmation, or disclosure about reading from disk and writing data into Origin.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.