Back to skill

Security audit

capgo-cloud

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Capgo workflow router, but users should treat its MCP and CLI setup as capable of changing real app releases and organization settings.

Install only if you intend to let an agent work with Capgo cloud resources. Prefer OAuth or secure secret storage over pasting API keys into chat, use read-only or narrowly scoped tokens by default, require explicit approval before release/channel/org mutations, and consider pinning the Capgo CLI version instead of running `@latest`.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
Capgo has two MCP servers. Use both when available.

- Hosted MCP: `https://api.capgo.app/mcp` (streamable HTTP). Nothing to install; the client signs in with OAuth, or sends `Authorization: Bearer <Capgo API key>`. The hosted MCP includes destructive tools, so use an API key with the smallest role the task needs (read-only for reporting). Covers apps, bundles, channels, progressive rollouts, devices, stats, update health, native build status and logs, webhooks, and push notifications. Example for Claude Code: `claude mcp add --transport http capgo https://api.capgo.app/mcp`, then `/mcp` to sign in.
- Local CLI MCP: `npx @capgo/cli@latest mcp` (stdio). Needed to upload a bundle from the build folder, request a native build, or run `doctor`.

No Capgo account yet: sign up at https://console.capgo.app (14-day free trial, no credit card). Docs: https://capgo.app/docs/ai/mcp/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The hosted MCP guidance tells users to supply a bearer API key and notes that the server exposes destructive tools, but it does not clearly warn against pasting secrets into chat-visible contexts or require confirmation boundaries for destructive actions. In an agent skill, this increases the chance of credential exposure and accidental high-impact operations against apps, releases, channels, or organizational resources.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs users to run npx @capgo/cli@latest mcp, which fetches and executes the latest package version at runtime without pinning. That creates a supply-chain risk: if the package is compromised or a breaking/malicious release is published, users may execute unreviewed code immediately in a workflow that can access build artifacts and deployment operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.