Back to skill

Security audit

Uplo Banking

Security checks for vulnerabilities and agentic risk

Overview

This banking knowledge skill is purpose-aligned, but it handles highly sensitive financial records with broad export, logging, and unpinned runtime execution risks that need review before use.

Review before installing. Use only with a pinned and reviewed MCP server, narrowly scoped short-lived UPLO tokens, server-side role and record-level access controls, explicit approval for `export_org_context`, and logging disabled or governed with consent, redaction, retention, and audit controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Error
Location
skill.json:25
Finding

Unpinned Third-Party Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: skill.json:25-30, README.md:21-27
Vulnerability Type: Unpinned dependency execution through npx
Risk Level: High

Vulnerable Code

skill.json:25-30:

json
"mcp": {
  "command": "npx",
  "args": [
    "-y",
    "@agentdocs1/mcp-server",
    "--http"
  ],

README.md:21-27:

json
{
  "mcpServers": {
    "uplo-banking": {
      "command": "npx",
      "args": ["-y", "@agentdocs1/mcp-server", "--http"],
      "env": {

Technical Analysis

The MCP configuration invokes npx -y with the package name @agentdocs1/mcp-server but does not specify an exact version or verify an integrity hash. If the package is not already available in the local cache, npx can retrieve the current registry version and execute it immediately. The -y option suppresses the normal installation confirmation.

Consequently, the code that runs can change after this Skill has been reviewed. A malicious package release, compromised maintainer account, registry compromise, or other supply-chain incident could introduce arbitrary code without requiring any changes to the audited project.

Although this is primarily an insecure dependency issue, it also creates a dynamic remote code retrieval path. The selected classification reflects the project's reliance on an unpinned third-party package.

Attack Path

  1. An attacker compromises the package publisher, publication credentials, or upstream package distribution process.
  2. The attacker publishes a malicious version of @agentdocs1/mcp-server.
  3. A user installs or starts the Skill on a system where the malicious version is not already pinned locally.
  4. npx -y retrieves the current package version without asking for confirmation.
  5. The malicious package executes with the privileges of the user running the Agent.
  6. The package can read process environment variables, including the configur ...[truncated 927 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @agentdocs1/mcp-server to a specific, reviewed version rather than resolving the latest available release.
  2. Use a lockfile and verify package integrity with a trusted cryptographic hash.
  3. Remove -y so that unexpected package retrieval is not silently accepted.
  4. Prefer installing the dependency during a controlled deployment phase rather than downloading it when the Skill starts.
  5. Configure the package manager to use an approved registry and enforce package provenance or signature verification where supported.
  6. Run the MCP server in a sandbox or container with restricted filesystem and network access.
  7. Provide the process with a narrowly scoped, short-lived API token rather than a broadly privileged credential.
  8. Add dependency monitoring and require security review before upgrading the pinned version.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:44
Finding

Conversation Metadata Is Transmitted Without an Explicit Consent or Redaction Step

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:44-47
Vulnerability Type: Unsafe transmission of potentially sensitive conversation metadata
Risk Level: Medium

Vulnerable Code

markdown
## Session End

Log the conversation:
```bash
mcporter call uplo-banking.log_conversation summary="Brief summary" topics='["topic1"]' tools_used='["search_knowledge"]'
text

### Technical Analysis

The session-end instruction directs the Agent to invoke `log_conversation` and transmit a summary, topic list, and tool-usage list to the configured remote UPLO instance. The instruction does not require user consent, preview of the transmitted payload, redaction of customer identifiers, or filtering of restricted banking information.

Because the Skill is specifically intended for KYC records, customer risk ratings, regulatory filings, transaction-monitoring alerts, loan history, and compliance materials, even a short summary or topic list may reveal regulated or confidential information. Tool-usage metadata can also disclose that a specific type of sensitive record was investigated.

The project states that classification levels must be respected, but it does not define an enforceable control for sanitizing the logging payload or preventing restricted data from entering it.

### Attack Path

1. A user discusses a customer, compliance investigation, examination finding, or other restricted banking matter.
2. The Agent uses UPLO search tools during the session.
3. At session end, the Skill instructs the Agent to create a conversation summary and topic list.
4. Sensitive identifiers, investigation context, or record categories are included in the generated metadata.
5. The `log_conversation` call transmits that metadata to the configured remote service.
6. The transmitted information may be stored, processed, or viewed according to remote-service controls that are not defined in the audited project.

### Impact Asse
...[truncated 665 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make conversation logging disabled by default and require explicit, informed user or administrator opt-in.
  2. Display the exact summary, topics, and usage metadata before transmission.
  3. Apply deterministic redaction to customer identifiers, account numbers, employee names, case references, and other regulated fields.
  4. Prohibit SAR-related content and other legally restricted material from entering logging payloads.
  5. Minimize the payload to operational telemetry that is strictly necessary.
  6. Document the destination, purpose, retention period, deletion process, and access controls for stored logs.
  7. Enforce server-side classification and data-loss-prevention controls rather than relying only on Agent instructions.
  8. Maintain an audit record of user consent and logging configuration without retaining the sensitive conversation content itself.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:31
Finding

Broad Organizational Context Export and Sensitive Banking Search Capabilities Lack Explicit Least-Privilege Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:31-34, identity-patch.md:3-7, skill.json:40-46
Vulnerability Type: Excessively broad access to regulated organizational information
Risk Level: High

Vulnerable Code

SKILL.md:31-34:

markdown
**Export org context:**
```bash
mcporter call uplo-banking.export_org_context
text

`identity-patch.md:3-7`:

```markdown
You are connected to your organization's banking knowledge base through UPLO. This gives you specialized access to KYC/AML records, regulatory filings (Call Reports, SARs, CTRs), risk management frameworks, loan processing documentation, transaction monitoring alerts, and compliance program records. When users ask about customer due diligence, regulatory requirements, or risk assessments, always query UPLO first to provide answers grounded in your institution's actual compliance and risk management practices.

Expect queries about KYC due diligence records and customer risk ratings, regulatory filing status and deadlines (OCC, FDIC, Fed), BSA/AML program documentation and SAR filings, loan application underwriting and approval history, transaction monitoring alerts and disposition, capital adequacy and stress testing results, and examination findings and remediation plans. Use `search_knowledge` for specific customer or filing lookups and `search_with_context` when the question requires understanding how a regulatory requirement intersects with risk management, compliance monitoring, and customer relationship management.

When presenting banking information, include customer identifiers (appropriately masked), regulatory filing references, and relevant dates. For compliance matters, cite the specific regulation and examination guidance. For risk data, present ratings with supporting rationale. Banking customer records, SAR filings, and examination materials are extremely sensitive — strictly respect classification tiers and regulatory disclosur
...[truncated 3491 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove export_org_context from the default capability set and enable it only for explicitly authorized administrative roles.
  2. Require a separate confirmation and approval workflow for bulk exports.
  3. Issue short-lived tokens with narrowly scoped capabilities, tenant restrictions, and record-level permissions.
  4. Bind authorization to the requesting end user's identity instead of relying solely on a shared MCP token.
  5. Enforce server-side role-based and attribute-based access controls for every query and returned record.
  6. Apply purpose limitation, field-level filtering, result-count limits, and classification-aware response filtering.
  7. Prevent SAR-related data and similarly restricted records from being returned through general-purpose search or export tools.
  8. Record immutable audit events for sensitive searches and exports, including requester identity, purpose, scope, and authorization decision.
  9. Require step-up authentication or compliance-officer approval for examination materials, transaction-monitoring cases, and organization-wide context.
  10. Treat content retrieved from the knowledge base as untrusted data and prevent embedded document instructions from initiating additional tools or exports.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This is a markdown file, so missing-warning checks apply to descriptions of behaviors that could affect user data or privacy. The export_org_context tool suggests bulk export of organizational knowledge, yet the README provides no caution about handling sensitive KYC/AML, regulatory, or confidential information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to Use' section is broad enough to trigger the skill during ordinary banking-related discussions, which can cause unnecessary access to sensitive organizational knowledge. In a banking/KYC/AML context, accidental invocation increases the chance of exposing regulated internal data or initiating logging/context-fetching behaviors without a clear user need.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill exposes an 'export_org_context' action without any warning, approval step, or stated restrictions on sensitive content handling. In a banking environment, organizational context may include internal structures, policies, regulatory mappings, or other sensitive metadata, so normalizing export behavior materially increases the risk of data overexposure or inappropriate disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to log the conversation at session end does not disclose to users that their prompts, summaries, topics, or tool usage may be stored. In a banking knowledge skill, conversations may contain customer, KYC, AML, risk, or regulatory information, making undisclosed retention and summarization a significant privacy, compliance, and data-governance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is designed to search and extract highly sensitive banking, KYC/AML, regulatory, and risk-management data, yet the manifest provides no user-facing warning, sensitivity notice, or guardrails around handling or exporting such information. In this domain, absent disclosure and handling constraints increase the likelihood of inappropriate use, over-collection, and exposure of regulated or confidential data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest advertises a banking knowledge-search skill, but it also declares an export_org_context capability that can enable broader extraction of organizational data than users may expect from simple search and structured retrieval. In a banking/KYC/AML context, this scope expansion is especially sensitive because exported context could include confidential internal directives, customer-related metadata, or other regulated information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

export_org_context is not clearly justified by the stated purpose of banking knowledge search, creating a privilege/scope mismatch between what the skill claims to do and what it can access or export. Such mismatches are dangerous because they can be abused by prompts or downstream agents to retrieve and package sensitive organizational information beyond the user's intended query flow.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The description is broad and does not clearly constrain what content may be searched or extracted, which can encourage overbroad invocation against sensitive banking datasets. In a high-sensitivity environment, vague scope increases the risk that users or agents treat the skill as a general-purpose extractor rather than a narrowly governed compliance/search tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.