Back to skill

Security audit

Mcps

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent MCP server manager, but it normalizes running unpinned third-party server packages that may receive database or GitLab credentials.

Install only if you are comfortable auditing and pinning the mcps package and every MCP server package you add. Use narrowly scoped, revocable credentials, avoid production database tokens until you have isolated the servers, and treat the DELETE SQL examples as dangerous unless run only in a test environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Packages Are Downloaded and Executed with Access to Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:5, SKILL.md:14-30, and SKILL.md:59-68
Vulnerability Type: Unpinned dependency execution and supply-chain exposure
Risk Level: Medium

The Skill instructs users to install or execute several third-party packages without pinning reviewed versions or verifying package integrity.

yaml
metadata: {"clawdbot":{"emoji":"🔌","requires":{"bins":["mcps"]},"install":[{"id":"npm","kind":"node","package":"@maplezzk/mcps","bins":["mcps"],"label":"Install mcps"}]}}
bash
npm install -g @maplezzk/mcps
bash
# Add fetch server (web scraping)
mcps add fetch --command uvx --args mcp-server-fetch

# Add PostgreSQL server
mcps add postgres --command npx --args @modelcontextprotocol/server-postgres --env POSTGRES_CONNECTION_STRING="${DATABASE_URL}"

# Add GitLab server
mcps add gitlab --command npx --args gitlab-mcp-server

The GitLab server configuration then provides a sensitive access token to one of these dynamically resolved executables:

json
{
  "name": "gitlab",
  "type": "stdio",
  "command": "npx",
  "args": ["gitlab-mcp-server"],
  "env": {
    "GITLAB_PERSONAL_ACCESS_TOKEN": "${GITLAB_TOKEN}",
    "GITLAB_API_URL": "https://gitlab.com/api/v4"
  }
}

Technical Analysis

Commands such as npm install, npx, and uvx can retrieve and execute package code from external registries. No explicit versions, lockfiles, checksums, signatures, or other integrity controls are specified. Consequently, the code executed when a user follows these instructions may differ from the code available when the Skill was audited.

This is particularly sensitive for gitlab-mcp-server: the spawned process is intentionally given GITLAB_PERSONAL_ACCESS_TOKEN. Any code running in that process can read the token from its environment. If the resolved package is compromised, replaced, or malicious, it can misuse or transmit the token ...[truncated 2201 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every package to a specific, reviewed version, including @maplezzk/mcps, mcp-server-fetch, @modelcontextprotocol/server-postgres, and gitlab-mcp-server.
  2. Use lockfiles and package-manager integrity metadata where supported. Verify package provenance, publisher identity, signatures, and checksums before execution.
  3. Avoid npx or uvx behavior that automatically retrieves an unspecified latest release. Preinstall verified artifacts or require execution with an exact version.
  4. Prefer a project-local or isolated installation over npm install -g.
  5. Run each MCP server in a container, sandbox, or dedicated low-privilege account with restricted filesystem and outbound network access.
  6. Supply only narrowly scoped, short-lived credentials to each server. The GitLab token should be limited to the minimum projects and API permissions required.
  7. Keep database and GitLab credentials isolated so that a server receives only the credential necessary for its own function.
  8. Disable verbose logging in environments containing secrets and verify that the manager and child processes do not log environment-variable values.
  9. Document package verification and upgrade-review procedures so that dependency updates do not occur automatically without security review.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The uvx example references mcp-server-fetch without version pinning, so users may execute an unexpected future release. In a tool that manages external MCP servers, this is especially relevant because the documented workflow normalizes running third-party server code locally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill recommends launching an MCP server package via npx without pinning an exact version, which makes installs non-reproducible and exposes users to supply-chain risk if a newer malicious or compromised release is published. Because this skill is specifically for managing and invoking MCP servers, users are likely to copy these commands directly, increasing practical exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example uses npx to fetch and execute gitlab-mcp-server without a pinned version, allowing whatever the latest published package is at execution time. That creates a supply-chain execution path where a compromised upstream release could run attacker-controlled code on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This repeated quick-start example again encourages unpinned installation/execution of mcp-server-fetch, reinforcing unsafe operational practice. Repetition in onboarding material increases the likelihood that users will adopt insecure defaults.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

mcps tools postgres --tool query --tool describe

Find tools containing "create"

mcps tools postgres --tool create

text

## Configuration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation includes a destructive SQL statement example without any warning, which can normalize unsafe usage and lead users to run harmful commands against production systems. In an MCP tool-calling context, examples are likely to be copied verbatim into real database management workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.