Back to skill

Security audit

US Card Forum

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its forum-search purpose, but it can be configured to download and run an environment-selected npm package while handling forum credentials.

Review the npm setup before installing. Prefer a preinstalled, verified Nitan MCP package with npx --no-install, avoid NITAN_MCP_ALLOW_INSTALL=1 unless you pin and verify the exact package, and configure forum credentials only through your MCP/client environment or API-key flow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/mcp_call.sh:77
Finding

Environment-Selected npm Package Can Be Downloaded and Executed at Runtime

Content
View full analysis
` - wrapper then uses `npx -y ` - Recommended hardening for frequent use: - install once globally: `npm install -g @nitansde/mcp@latest` ``` Related instruction from `SKILL.md:85-86`: ```markdown - These commands assume `nitan-mcp` is already installed and available to `npx --no-install`. - If the user explicitly opts into install-on-demand mode, substitute a pinned package form such as `npx -y @nitansde/mcp@ ...`. ``` ### Technical Analysis The package passed to `npx` is obtained directly from the `NITAN_MCP_PACKAGE` environment variable. When `NITAN_MCP_ALLOW_INSTALL=1`, the wrapper invokes `npx -y` with that value without enforcing an allowlist, validating the package name, or requiring an exact immutable version. Using a Python argument array prevents shell metacharacter injection, but it does not prevent execution of a malicious or compromised npm package. `npx -y` may retrieve the selected package and execute its code, including applicable package lifecycle behavior, with the permissions and environment of the Skill process. The document ...[truncated 2145 chars]
Remediation
View remediation
` for installation. Reject paths, URLs, Git references, ranges, tags such as `latest`, and unrelated package names. 3. Remove the recommendation to install `@latest`. Document a reviewed exact version, such as: ```bash npm install -g @nitansde/mcp@1.2.3 ``` 4. Prefer eliminating runtime package installation entirely. Require administrators or users to install and verify the dependency separately, then retain only the `npx --no-install nitan-mcp` path. 5. Where runtime retrieval is unavoidable, verify package provenance and integrity before execution. Pin an exact version and validate expected registry metadata or integrity hashes. 6. Launch the MCP process with a minimized environment. Pass only variables required by the server rather than inheriting the complete Agent environment. 7. Run the external MCP package in a sandbox or restricted account with minimal filesystem and network permissions, especially when authentication variables are present. 8. Fail closed when `NITAN_MCP_ALLOW_INSTALL` contains any value other than the documented default, and emit a clear warning before initiating network retrieval or package execution. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description emphasizes secure local MCP server usage for uscardforum.com search, reading, monitoring, and auth setup guidance. The actual code shown does not implement or expose those wrapper/install-security behaviors; instead, it directly wraps a specific MCP call, "discourse_list_funny_topics." That is a materially different and more specific capability than what is declared, and the declared description does not mention humorous/funny-topic listing or this Discourse-specific operation. Therefore this chunk is mismatched to the stated purpose.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

md
This skill is intended for ClawHub publishing review.

- Keep instructions explicit and auditable. No hidden behavior.
- Do not include install steps that execute remote scripts (`curl | bash`, encoded payloads, etc.).
- Explicitly acknowledge npm package execution path and related env vars in skill docs/metadata.
- Do not ask users to paste secrets in chat. Credentials must be configured in MCP client env.
- Do not print or transform secret values in outputs.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares shell and environment-variable driven behavior but does not explicitly scope or constrain allowed tools/permissions. That increases the attack surface because a host agent may expose broader execution capabilities than the skill actually needs, making misuse or prompt-driven command execution easier if the surrounding platform relies on declarative tool scoping.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The metadata advertises an install-on-demand command using npx -y @nitansde/mcp@<version>, but as written it references an unpinned package form in the finding and normalizes runtime package selection through an environment variable. Any pathway that allows fetching a package without strict pinning and validation risks executing unexpected code from the npm registry or from a tampered package selection value.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
- pin exact versions when enabling install mode
- Communication model: MCP client <-> local server subprocess over stdin/stdout (JSON-RPC).
- Do not require local repository files or paths such as `node dist/index.js`, `src/`, or `requirements.txt`.
- Do not ask the user to clone this repo.

## Declared environment variables

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
- pin exact versions when enabling install mode
- Communication model: MCP client <-> local server subprocess over stdin/stdout (JSON-RPC).
- Do not require local repository files or paths such as `node dist/index.js`, `src/`, or `requirements.txt`.
- Do not ask the user to clone this repo.

## Declared environment variables

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The auth setup guidance includes an install-on-demand substitution path that can invoke npx -y against a package identifier, which is remote code execution by design if the package must be downloaded. Even though the text recommends pinning, the presence of an install-enabled fallback in a skill increases supply-chain risk, especially if operators copy commands without rigorous version pinning and provenance checks.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
- Keep instructions explicit and auditable. No hidden behavior.
- Do not include install steps that execute remote scripts (`curl | bash`, encoded payloads, etc.).
- Explicitly acknowledge npm package execution path and related env vars in skill docs/metadata.
- Do not ask users to paste secrets in chat. Credentials must be configured in MCP client env.
- Do not print or transform secret values in outputs.
- Avoid obfuscation or ambiguous install logic; uploaded skills are security-scanned and publicly reviewable.
- Verify npm package identity before use and prefer pinned versions over floating `@latest` when possible.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script can execute npx -y <package> when NITAN_MCP_ALLOW_INSTALL=1, which may download and run a package. Although this behavior is controlled by an environment variable, the file provides no confirmation prompt, user-facing disclosure, or explanatory comment warning that code may be installed and executed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool descriptions embed Chinese badge names ("精彩的话题" and "难绷的话题") in the user-facing instructions without indicating that the skill supports multiple languages or that this locale choice is optional. This can violate language/locale policy because the skill presents a fixed language experience without explicit user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.