Back to skill

Security audit

mcporter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a thin, disclosed wrapper for using the mcporter CLI to manage and call MCP servers, but users should treat it as a powerful integration surface.

Install only if you trust the mcporter project and the Homebrew tap. Before running mcporter auth, config, ad-hoc server, or call commands, check which MCP server is being used and what the target tool can access or change, especially for servers connected to accounts, local files, or external services.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party Homebrew Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 4–11
Vulnerability Type: Unpinned dependency from a third-party Homebrew tap
Risk Level: Medium

Vulnerable Code Snippet

yaml
metadata: {"clawdbot":{"emoji":"🔌","os":["darwin","linux","windows"],"requires":{"bins":["mcporter"]},"install":[{"id":"brew","kind":"brew","formula":"pdxfinder/tap/mcporter","bins":["mcporter"],"label":"Install mcporter (brew)"}]}}

# mcporter

Use `mcporter` to manage MCP (Model Context Protocol) servers and tools.

## Requirements
- `mcporter` CLI installed (via Homebrew: `brew install pdxfinder/tap/mcporter`)

Technical Analysis

The skill directs users or agents to install mcporter from the custom third-party Homebrew tap pdxfinder/tap. The dependency is not pinned to an audited version or repository commit, and the instructions provide no checksum or signature verification.

Because the formula is mutable, the code executed during installation can change after this skill has been reviewed. A compromise of the tap repository, its maintainer account, or its upstream release-distribution process could cause Homebrew to retrieve and execute attacker-controlled installation logic. This is a supply-chain risk; the audit did not find evidence that the current package is malicious.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, a maintainer account, or the referenced upstream artifact-distribution channel.
  2. The attacker modifies the formula or release artifact to include malicious installation-time or runtime code.
  3. A user or automated agent follows the skill metadata or documented command:
    bash
    brew install pdxfinder/tap/mcporter
    
  4. Homebrew resolves the mutable third-party formula and downloads the compromised content.
  5. The malicious code executes with the privileges of the account performing the installation.
  6. If the compromised CLI is later used for authentication or MCP calls, it may also access ...[truncated 716 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed release version or an immutable tap repository commit rather than relying on the mutable latest formula.
  2. Publish and verify cryptographic checksums or signatures for downloaded release artifacts.
  3. Prefer an official, trusted distribution channel when one is available.
  4. Document the expected package version, source repository, checksum, and verification procedure directly in the skill.
  5. Avoid unattended installation or automatic execution of third-party formulas without explicit user approval.
  6. Review the formula and its upstream artifacts before updating the pinned version.
  7. Run the CLI with least privilege and restrict access to unrelated credentials and sensitive files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes commands that can directly invoke MCP tools over HTTP or stdio, perform authentication, and edit mcporter configuration, but it provides no safety guidance about network effects, credential handling, or the risks of changing persistent config. This increases the chance that an agent or user will execute high-impact actions without understanding that tool calls may reach external services or alter local trust boundaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.