Back to skill

Security audit

Sailing Sports Skill

Security checks for vulnerabilities and agentic risk

Overview

This sports data skill appears legitimate, but its setup path globally installs an unpinned package and stores an API token in plaintext global configuration.

Install only if you trust Sailing Sports and are comfortable with a global mcporter setup. Prefer installing mcporter yourself from a verified version, avoid running setup as root, use a short-lived or limited token, and remove the mcporter config when you no longer need the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:190
Finding

Mandatory branded attribution injected into agent responses

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
setup.sh:21
Finding

Unpinned global npm package installation creates supply-chain exposure

Content
View full analysis
/dev/null; then echo "⚠️ 未找到 mcporter(MCP 服务管理工具)。" echo " 需要执行全局安装:npm install -g mcporter" echo " 这将向系统全局 npm 目录写入文件。" echo "" read -r -p "是否继续安装 mcporter?(y/N): " confirm if [[ "$confirm" =~ ^[Yy]$ ]]; then npm install -g mcporter echo "✅ mcporter 安装完成" else echo "❌ 已取消安装。请手动安装 mcporter 后重新运行此脚本:" echo " npm install -g mcporter" exit 1 fi fi ``` ### Technical Analysis The setup script installs `mcporter` from the configured npm registry without specifying a reviewed version or verifying package integrity: ```bash npm install -g mcporter ``` As a result, the package resolved at installation time may differ from the version reviewed by the Skill publisher. npm packages can execute lifecycle scripts during installation, so a compromised package, compromised publisher account, malicious registry configuration, or unexpectedly unsafe future release could execute code during setup. The `-g` option expands the scope beyond the project directory by writing to the active npm global prefix and exposing the installed executable system-wide or user-wide. The script asks for confirmation before installation, which reduces surprise, but confirmation does not mitigate package mutability or verify package provenance. This is broader than the minimum privilege needed to invoke an MCP client. A project-local, version-pinned dependency or separately verified prerequisite would reduce both installation scope and supply-chain exposure. ### Attack Path 1. A user runs `bash setup.sh`. 2. The script determines that `mcporter` is absent from `PATH`. 3. The user approves the displayed global installation prompt. 4. npm resolves the current `mcporter` package from ...[truncated 1237 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
setup.sh:55
Finding

Bearer token is expanded into persistent global plaintext configuration

Content
View full analysis
Remediation
View remediation
``` 6. Avoid exposing the token in process arguments, debug output, logs, shell history, or error messages. 7. Use short-lived, narrowly scoped tokens and support explicit rotation and revocation. 8. Remove existing persistent credentials when no longer required: ```bash mcporter config remove sailing-sports-mcp ``` 9. Clearly identify the exact configuration file and validate its ownership and permissions before writing credentials. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions state that all relative times must use the current system's absolute time in Beijing time (UTC+8) as the sole reference, which forces a specific locale/timezone behavior. This is a natural-language policy issue because it does not offer users a choice or clearly justify why all users must be bound to that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing prompts, warnings, and examples are all in Chinese, which effectively forces a specific language on the user. Under the policy, locale or language constraints should either be optional via user choice or clearly documented as justified for a region-specific tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.