T08 · Insecure Dependencies
- Location
SKILL.md:116- Finding
Unpinned MCP Package Is Downloaded and Executed with a Secret API Key
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Verfi consent-verification integration, but it needs Review because it enables broad form-activity recording and secret-key powered tooling without enough scoping, consent, or supply-chain controls.
Install only after reviewing Verfi's privacy, consent, retention, and tenant-access controls. Use explicit user notice and legally appropriate consent before session recording, limit SDK deployment to required forms, use CSP or integrity/version controls where possible, and provide narrowly scoped, rotatable secret keys. Avoid the unpinned npx MCP configuration in production unless you pin and verify the package and run it in a restricted environment.
SKILL.md:116Unpinned MCP Package Is Downloaded and Executed with a Secret API Key
SKILL.md:23Mutable Remote SDK Executes with Full Page-Origin Access
The skill explicitly states that the SDK auto-records mouse movements, clicks, keystrokes, and scroll activity, but it does not pair that capability with a clear, prominent warning about the privacy implications or limits on capture. In a lead-generation context, this can result in covert collection of sensitive behavioral and form data, creating significant privacy, compliance, and consent risk if deployed without explicit notice and appropriate controls.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Verfi API Reference
Base URL: `https://api.verfi.io/tenant/v1`
All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Verfi API Reference
Base URL: `https://api.verfi.io/tenant/v1`
All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Verfi API Reference
Base URL: `https://api.verfi.io/tenant/v1`
All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Verfi API Reference
Base URL: `https://api.verfi.io/tenant/v1`
All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Verfi API Reference
Base URL: `https://api.verfi.io/tenant/v1`
All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`
The API explicitly documents cross-tenant session lookup, allowing any tenant with the appropriate scope to search any session by Verfi ID or proof URL. In a consent-verification product, this exceeds least-privilege expectations and creates an authorization/privacy risk because tenant boundaries are intentionally bypassed for records that may reveal consent status and related metadata.
The documented lookup and proof endpoints expose privacy-sensitive data across tenant boundaries, including hashed identifiers, consent verification results, interaction telemetry, device attributes, and proof URLs. Even when some PII is hashed, these data elements can enable correlation, reidentification, targeted abuse, or unauthorized inspection of user consent records, especially when accessible cross-tenant and without prominent privacy/security constraints.
The documentation describes an SDK that automatically records extensive behavioral telemetry across forms, including mouse movements, clicks, scrolls, typing patterns, consent interactions, device metadata, and hashed PII, but it does not clearly warn implementers to obtain informed user consent or provide prominent notice before collection. In a lead-generation/TCPA compliance context, this is risky because developers may deploy the SDK exactly as documented, resulting in privacy-invasive monitoring and potential regulatory or consent failures despite the product's compliance-oriented purpose.
No suspicious patterns detected.