Back to skill

Security audit

Microsoft Learn MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Microsoft Learn documentation connector with disclosed remote MCP use and no hidden execution or data-access behavior.

Before installing, understand that this skill configures mcporter to call a remote Microsoft Learn MCP server for public documentation searches and page fetches. Use it for Microsoft documentation tasks, and specify locale or language parameters when you need non-default results.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guidance suggests broad prompt triggers like "add 'search Microsoft Learn' or 'fetch full doc' to prompts to trigger tool usage," which can cause the agent to invoke external tools based on loosely scoped user phrasing rather than explicit intent boundaries. In an agent skill that connects to a live remote MCP server with dynamic tools, this increases the chance of over-triggering tool calls, unintended remote requests, and prompt-injection exposure through fetched content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown explicitly says the locale defaults to "en-us if not specified," which can amount to a language/locale policy issue when the skill behavior is biased toward a specific locale without user opt-in. The file does mention locale as an optional parameter elsewhere, but it does not clearly instruct users to choose their preferred locale or frame the default as an opt-in behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.