Back to skill

Security audit

Mentions Discover

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow MentionsAPI integration that sends a user-confirmed brand query and its declared API key to the disclosed MentionsAPI endpoint.

Install only if you intend to use MentionsAPI and are comfortable providing MENTIONSAPI_KEY for paid query-discovery calls. Confirm the brand and industry before each call, and avoid using the optional unpinned npx MCP alternative unless you separately trust and pin that package.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tainted flow: 'req' from os.environ.get (line 65, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · handler.py (reported line 76)May include surrounding context.

python
"Accept": "application/json",
            },
        )
        with urllib.request.urlopen(req, timeout=TIMEOUT_SECONDS) as resp:
            raw = resp.read().decode("utf-8")
            return json.loads(raw) if raw else {}
    except urllib.error.HTTPError as e:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares required environment access and clearly depends on networked API calls, but it does not explicitly define a tool/permission scope such as allowed-tools or permissions. That omission can cause the runtime to grant broader-than-necessary capabilities or make review harder, increasing the risk of unintended data exposure from environment variables or unexpected outbound requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Referencing an MCP server via an unpinned package name (npx @mentionsapi/mcp) allows whatever version is current at install/run time to be executed. If the upstream package is compromised, publishes a breaking or malicious update, or resolves differently over time, users may run unreviewed code with network and possibly credential access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tests/test_handler.py (reported line 47)May include surrounding context.

python
with patch.dict(os.environ, {"MENTIONSAPI_KEY": "lvk_test"}):
            handler.discover_queries(brand="Linear", industry="project management", count=25)
        req = mock_urlopen.call_args[0][0]
        self.assertEqual(req.full_url, "https://api.mentionsapi.com/v1/discover")
        self.assertEqual(req.get_method(), "POST")
        body = _sent_body(mock_urlopen)
        self.assertEqual(body["brand"], "Linear")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tests/test_handler.py (reported line 76)May include surrounding context.

python
with patch.dict(os.environ, {"MENTIONSAPI_KEY": "lvk_test"}):
            handler.discover_queries(brand="Linear", industry="project management", count=25)
        req = mock_urlopen.call_args[0][0]
        self.assertEqual(req.full_url, "https://api.mentionsapi.com/v1/discover")
        self.assertEqual(req.get_method(), "POST")
        body = _sent_body(mock_urlopen)
        self.assertEqual(body["brand"], "Linear")

Static analysis

No suspicious patterns detected.