Back to skill

Security audit

monday.com

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate monday.com integration, but it asks users to run an unpinned MCP package with a monday.com API token and gives the agent broad business-data authority.

Review before installing. Use a dedicated, least-privilege monday.com token if possible, store it only in an approved secrets mechanism, and avoid the `@latest` MCP install pattern unless you trust and pin the package version. Confirm destructive changes, file uploads, webhook destinations, and workspace-level changes explicitly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:64
Finding

Mutable MCP Dependency Is Downloaded and Executed with API Token Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 64–68
Vulnerability Type: Insecure dependency execution and supply-chain exposure
Risk Level: High

Vulnerable Code

json
"command": "npx",
"args": ["-y", "@mondaydotcomorg/monday-api-mcp@latest"],
"env": {
  "MONDAY_API_TOKEN": "<your-api-token>"
}

Technical Analysis

The MCP configuration invokes npx with -y and the mutable @latest package tag. Each installation can therefore retrieve and execute a package version that did not exist when this Skill was reviewed. The automatic confirmation option also removes an opportunity for the operator to inspect the selected version.

The downloaded process is explicitly given MONDAY_API_TOKEN. Consequently, the trust placed in the package extends to a sensitive credential and all monday.com resources accessible through that token. Although the referenced package appears to be associated with monday.com, using an unpinned release still leaves the effective executable payload dependent on future registry and publisher state.

This behavior is not required at its current privilege level. The declared integration can operate with a reviewed, exactly pinned MCP release or use the documented GraphQL fallback without dynamically executing the latest package.

Attack Path

  1. An attacker compromises the package publisher account, release pipeline, package registry, or a future package release.
  2. The attacker publishes malicious code under a version selected by the @latest tag.
  3. An operator or Agent starts the configured MCP server.
  4. npx -y downloads and executes the mutable release without interactive review.
  5. The malicious process reads MONDAY_API_TOKEN from its environment.
  6. It can send the token or accessible monday.com data to an attacker-controlled service, issue unauthorized API operations, or use any additional local privileges available to the subprocess.

...[truncated 743 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version, for example:
    json
    "args": ["-y", "@mondaydotcomorg/monday-api-mcp@X.Y.Z"]
    
  2. Use a lockfile and registry integrity hashes so the installed artifact is reproducible and tampering is detectable.
  3. Update dependencies only through a controlled review process that examines release provenance, changes, and security advisories.
  4. Prefer a preinstalled and verified executable rather than downloading code at invocation time.
  5. Run the MCP process in a sandbox with restricted filesystem access, an allowlisted network policy, and no access to unrelated environment variables or credentials.
  6. Use a dedicated, least-privilege monday.com credential where supported. Limit its permissions and rotate it immediately if dependency compromise is suspected.
  7. Consider the documented direct GraphQL fallback when MCP-specific functionality is unnecessary, while continuing to protect the authorization header and restricting requests to the official monday.com endpoint.
  8. Avoid relying on -y for security-sensitive installations; require explicit administrative review for dependency changes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill explicitly instructs how to obtain a personal API token, which is highly sensitive credential material. In combination with the broad operational scope and signup guidance, this normalizes credential acquisition by the agent and increases the risk of unauthorized access, misuse, or mishandling of long-lived tokens.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
- **Resources** — links to docs, SDK, community


## Setup when you have account but don't have access token

1. Go to **monday.com → Profile picture → Developers → My Access Tokens**
2. Copy your **Personal API V2 Token**

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Directing users to copy a personal API token into agent configuration increases exposure of a high-value secret and can lead to insecure handling if the platform's storage model is weak or if logs/memory capture configuration steps. Personal tokens often grant broad access to business data, so poor secret-handling here has significant blast radius.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
## Setup when you have account but don't have access token

1. Go to **monday.com → Profile picture → Developers → My Access Tokens**
2. Copy your **Personal API V2 Token**
3. Store it securely in your agent's environment or config (e.g. via `openclaw config set` or your platform's secrets manager)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is extremely broad and can cause the skill to activate for many generic monday.com-related requests, including sensitive administrative or workflow actions. Overbroad triggering increases the chance of unnecessary access to business data or execution of high-impact actions when a narrower skill or explicit confirmation should have been used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The phrase "Manage everything on monday.com" gives the skill effectively unlimited operational scope without defining safe limits. In a business SaaS context, that ambiguity is risky because it can normalize broad data access and high-privilege mutations across boards, users, workspaces, files, and automations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill includes step-by-step instructions to create a new monday.com account by solving an anti-bot challenge and then obtaining an API token. That behavior exceeds the stated need to manage an existing user's monday.com resources and encourages automated account creation plus credential acquisition, which can facilitate platform abuse or unauthorized provisioning.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The file-upload endpoint enables transmission of potentially sensitive local files to an external service, and the skill does not impose strong guardrails around file selection, consent, or data classification. In a business workflow context, this can lead to unintended exfiltration of confidential documents or oversized uploads beyond user expectations.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
Use the GraphQL API directly when MCP tools don't cover the operation (webhooks, file uploads, subitems, pagination, user/workspace queries, activity logs).

- **Endpoint:** `https://api.monday.com/v2` (POST, JSON body with `query` field)
- **File uploads:** `https://api.monday.com/v2/file` (multipart POST, max 500MB)
- **Auth:** Include your API token in the request header (see [API docs](https://developer.monday.com/api-reference))
- **API version:** Include `API-Version: 2024-10` header. Check [developer.monday.com/api-reference](https://developer.monday.com/api-reference) for the current stable version.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
Full query and mutation examples for the monday.com GraphQL API.

**Endpoint:** `POST https://api.monday.com/v2`
**Headers:** `Authorization: <your-token>`, `Content-Type: application/json`, `API-Version: 2024-10`

## Queries

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/graphql-examples.md (reported line 5)May include surrounding context.

md
Full query and mutation examples for the monday.com GraphQL API.

**Endpoint:** `POST https://api.monday.com/v2`
**Headers:** `Authorization: <your-token>`, `Content-Type: application/json`, `API-Version: 2024-10`

## Queries

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes a delete_item mutation example that can remove user data, but the surrounding documentation provides no warning that the action is destructive or may be irreversible. Under the markdown criteria for missing user warnings, destructive operations that affect user data should be explicitly disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The webhook example encourages sending board events to an arbitrary external URL without any warning about data sharing, trust boundaries, or endpoint validation. In an agent context, this can lead to unintended exfiltration of board metadata, updates, and workflow activity to third-party infrastructure controlled by a user or attacker.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
# monday.com

Manage everything on monday.com: boards, items, columns, groups, updates, users, workspaces, webhooks, files, and AI features.

## If you need to signup new account this is how to Sign Up

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

md
- Don't share board data across different users' sessions or conversations
- monday.com customer data is never used to train AI models

**Permissions:**
- Personal API tokens inherit the user's UI permissions — if they can't see a board in the UI, the API won't return it
- Always verify board access before performing operations
- Don't delete items, boards, or groups without explicit user confirmation

Static analysis

No suspicious patterns detected.