Back to skill

Security audit

firstdata

Security checks for vulnerabilities and agentic risk

Overview

The skill is broadly coherent, but its setup asks users to run an unpinned npm command and handle a long-lived API token without enough safety guidance.

Before installing, prefer the manual MCP configuration or use a pinned, trusted `mcporter` version instead of an unversioned `npx` command. Treat `FIRSTDATA_API_KEY` as a secret: keep it out of source control and logs, store it in a secret manager or protected environment variable, and rotate it if exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:68
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 68
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
npx mcporter config add firstdata https://firstdata.deepminer.com.cn/mcp --header 'Authorization=Bearer ${FIRSTDATA_API_KEY}'

The same command is also documented in references/firstdata-register.md, line 106.

Technical Analysis

The documented command invokes mcporter through npx without specifying an exact package version, lockfile, or integrity hash. If the package is not already available in a trusted local installation, npx may retrieve and execute the package version currently selected by the npm registry.

Consequently, the executable code run by users can change after this Skill has been reviewed. A compromised package release, maintainer account, npm dependency, or registry resolution path could introduce arbitrary code without requiring changes to this repository.

The command also references FIRSTDATA_API_KEY. A malicious package executing in the user's environment may be able to read that environment variable and other credentials accessible to the current process.

Attack Path

  1. An attacker compromises the mcporter package, one of its runtime dependencies, or an authorized publisher account.
  2. The attacker publishes a malicious version that is selected when an unversioned npx mcporter command is resolved.
  3. A user follows the Skill documentation and runs the command.
  4. npx downloads and executes the malicious package with the user's local operating-system privileges.
  5. The package can access files, environment variables, network resources, and configuration writable by that user.
  6. The malicious process may steal FIRSTDATA_API_KEY, modify MCP configuration, install additional payloads, or perform other actions allowed by the user's account.

Impact Assessment

Successful exploitation provides arbitrary code execution with the p ...[truncated 632 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin mcporter to an exact version that has been reviewed, rather than resolving the current registry version:
bash
npx --yes mcporter@<audited-exact-version> config add firstdata https://firstdata.deepminer.com.cn/mcp --header 'Authorization=Bearer ${FIRSTDATA_API_KEY}'
  1. Validate the selected package version and its dependency tree before recommending it.
  2. Use a lockfile and registry integrity metadata in a controlled installation workflow.
  3. Prefer executing a preinstalled, trusted CLI rather than allowing npx to download code at invocation time.
  4. Make the documented manual JSON configuration the primary setup method because it does not require executing a remotely resolved npm package.
  5. Run setup with least privilege and ensure the invoking environment exposes only the required secret.
  6. Add guidance for rotating the long-lived bearer token if package or workstation compromise is suspected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs users to run npx mcporter without pinning a specific package version, which can result in execution of whatever version is current at install time. This creates a supply-chain risk: a compromised upstream release, typosquatted dependency resolution, or unexpected breaking change could execute attacker-controlled code on the user's system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to save and reuse a 365-day bearer token but provides no warning about secure storage, redaction, least privilege, rotation, or avoiding commits/logging. In a registration/onboarding document, that omission materially increases the chance of credential leakage, which would allow unauthorized API access for up to a year.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The documented response message is 验证成功,token 已激活, which indicates the skill/API may return Chinese text by default. The file does not state that the service is Chinese-only, region-specific, or that users can opt into another language, so this appears to be a locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.