Back to skill

Security audit

Quotewise semantic quote search via MCP

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate quote-search skill, but its normal setup and use instructions rely on unpinned npm commands and may store an API key in persistent home-scoped configuration.

Review this before installing if your environment has sensitive files or credentials. Prefer pinned package versions, run setup from a least-privilege shell, avoid exposing API keys in command-line arguments, and confirm how mcporter stores and removes home-scoped Authorization headers.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned npm Packages Are Downloaded and Executed Through npx

Content
View full analysis
" key=value --output json ``` Configuration invocation from `SKILL.md:25-28`: ```bash npx mcporter config add quotewise https://mcp.quotewise.io/mcp \ --header "User-Agent=quotewise-skill/1.0" --scope home ``` Guided setup command documented in `SKILL.md` and `README.md`: ```bash npx @quotewise/mcp setup ``` Equivalent unpinned `npx mcporter` and `npx @quotewise/mcp setup` commands are repeated throughout both documentation files. ### Technical Analysis `npx` can resolve, download, and immediately execute an npm package when an appropriate local package is not already installed. The commands do not specify reviewed package versions or verify package integrity. Consequently, the code executed by these instructions can change after the skill has been audited. This creates a software supply-chain exposure. A compromised maintainer account, malicious package release, registry compromise, or unexpected package resolution could cause users to retrieve and execute attacker-controlled package code. No evidence was found that the packages are currently malicious; the vulnerability is the unsafe, mutable dependency execution pattern. ### Attack Path 1. An attacker compromises the npm package, its maintainer account, or its publication pipeline. 2. The attacker publishes a malicious version under `mcporter` or `@quotewise/mcp`. 3. A user follows the documented command without specifying a reviewed version. 4. `npx` resolves and downloads the malicious release. 5. Package lifecycle behavior or CLI entry-point code ...[truncated 925 chars]
Remediation
View remediation
call ... npx --yes @quotewise/mcp@ setup ``` 2. Replace placeholders with maintained version numbers and update them only after reviewing the corresponding package release. 3. Prefer installation through a project manifest and lockfile rather than repeated ad hoc downloads. 4. Verify package provenance, signatures, and registry integrity metadata where supported. 5. Disable or tightly control lifecycle scripts when they are unnecessary. 6. In higher-risk environments, execute third-party setup tools inside a sandbox or container with minimal filesystem, credential, and network access. 7. Document the expected package publisher, registry, version, and integrity digest so users can detect unexpected package resolution. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:43
Finding

Bearer API Key Is Expanded into Process Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (29)

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to execute npx mcporter without pinning a specific version. npx will fetch the latest package at execution time, so a compromised publisher account, malicious update, or dependency hijack could result in arbitrary code execution on the user's machine. In this skill context, the command is presented as the standard installation/use path, which increases exposure because users are likely to copy-paste it directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This command uses npx mcporter without a pinned version, causing runtime retrieval of whatever version is current in the npm registry. If the package or one of its transitive dependencies is maliciously updated, users following the README could execute attacker-controlled code. Because this is an agent skill README, the likelihood of direct copy-paste is high, making the supply-chain risk more operationally relevant.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The unpinned npx mcporter invocation introduces a supply-chain execution risk because users are instructed to run code resolved at the moment of execution. That means trust is delegated to the current state of the npm package and its dependencies rather than a reviewed, fixed version. The skill context does not mitigate this; if anything, setup instructions embedded in documentation make unsafe execution patterns more likely to be reused.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README again instructs execution of npx mcporter without version pinning. This creates a true supply-chain vulnerability pattern because the user may run newly published code that was never reviewed by the skill author or operator. Since the command configures authorization-bearing access to a remote MCP endpoint, compromise of the CLI could also expose headers or tokens handled during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This example call uses an unpinned npx mcporter, which means the fetched executable may change over time and could become malicious. A compromised package could execute arbitrary local code, exfiltrate environment variables, or alter requests sent to the configured MCP service. The documentation context makes this dangerous because these examples are framed as normal usage, not as development-only commands.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Running npx mcporter without a fixed version allows whatever package version is currently published to execute on the host. That is a known supply-chain risk and qualifies as a true vulnerability in security-sensitive setup documentation. Here the risk is amplified because the command is part of operational agent workflows and may be executed in environments that also hold credentials or sensitive prompts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The command relies on an unpinned npm package through npx, exposing users to malicious or compromised future releases. Because npx executes code immediately after retrieval, exploitation can directly lead to arbitrary command execution on the invoking machine. In the context of a public README for a skill, this is especially risky because users may trust the project and not independently vet the package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This unpinned npx mcporter example carries the same supply-chain exposure: the effective code executed is not stable or reviewable from the README alone. If the package is hijacked or its dependencies are poisoned, a user invoking the example could suffer local compromise or data theft. The skill context does not justify the risk, as pinning would preserve functionality while materially improving safety.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This README example executes npx mcporter without version pinning while performing collection-management operations. The primary danger remains arbitrary code execution via package substitution or malicious update, and those workflows may also involve API credentials or user data that a malicious binary could capture. Because this is a user-facing command example, the unsafe pattern is likely to be copied verbatim.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The second collection-management example also uses floating npx mcporter, creating a real package-supply-chain execution risk. Attackers who gain control of the package or publish a malicious dependency version could execute code under the user's account and potentially access local files, secrets, or outbound requests. Given that this skill encourages agent and human reuse, the dangerous pattern is broadly propagated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The guided setup command uses npx @quotewise/mcp without version pinning, so users will execute the latest package code at runtime. This is a classic supply-chain risk that can result in arbitrary code execution if the package or publishing account is compromised. Because the package name is directly controlled by the skill vendor, users may be even more inclined to trust and run it without scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This repeated npx @quotewise/mcp setup command is likewise unpinned and therefore subject to mutable package-resolution risk. A malicious new release could execute arbitrary code, harvest local configuration, or tamper with MCP client setup. The repetition in a 'For Your Human' section expands the audience beyond technical operators, increasing the chance of unsafe execution by less cautious users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation guidance is very broad: 'User asks about quotes, wants inspiration, half-remembers something, or needs to check attribution.' Such everyday-language triggers can cause the skill to be invoked in loosely related conversations, increasing unintended data flow to the external MCP service and making overuse of the tool more likely than necessary.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs users to run npx mcporter without pinning an exact package version, which allows whatever version is current in the registry at execution time to be fetched and run. If the package, a dependency, or the publishing account is compromised, this becomes arbitrary code execution on the user's machine, and the risk is amplified because the tool is then used to send headers and API tokens to remote endpoints.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This setup command uses unpinned npx mcporter, so the package resolved at runtime may differ over time and could be malicious if the registry supply chain is compromised. Because the command writes persistent client configuration, a malicious package could also establish lasting unsafe settings beyond a single invocation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The authentication example combines unpinned npx mcporter execution with an Authorization header containing $QUOTEWISE_API_KEY. A compromised package could exfiltrate the bearer token or alter how headers are handled, turning a documentation example into a credential theft path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This anonymous-use example still executes an unpinned npx mcporter package, exposing users to registry or dependency compromise even without credentials. The absence of auth lowers direct secret exposure, but arbitrary local code execution remains possible.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The semantic search example relies on an unpinned package fetched and executed at runtime. Any compromise of the package supply chain could let an attacker run code locally under the user's account when they follow the skill instructions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This search-by-person command uses the same unpinned npx mcporter pattern, creating supply-chain execution risk. While the command itself is low-privilege in intent, the execution model allows arbitrary code to run before the network request is even made.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This source-search example again depends on runtime resolution of an unpinned npm package. The skill context does not reduce the core issue: users are being told to execute code from the package registry without version control or integrity guarantees.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The exact-text lookup example repeats the same unpinned npx mcporter execution pattern. This is dangerous because any future malicious release or dependency hijack would transparently affect users who follow the documentation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The attribution-check example still uses unpinned npx mcporter, preserving the same supply-chain execution weakness. The quote-related domain is benign, but the local execution mechanism is independent of business purpose and remains risky.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This similar-quotes command uses an unpinned npm executor and therefore inherits package substitution and malicious update risk. A user copying the command could run attacker-controlled code if the package supply chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The random-quote example normalizes execution of an unpinned remote package, which can be abused for arbitrary code execution through supply-chain compromise. The operation appears harmless, making it more likely users will run it casually without recognizing the risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The collections status command uses unpinned npx mcporter in a section explicitly marked as requiring authentication. Even if the specific status call is low-risk, the surrounding authenticated workflow increases the chance users run related commands with tokens configured, making supply-chain compromise more damaging.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.