Back to skill

Security audit

Uplo Data Analytics

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for UPLO analytics knowledge search, but it runs an unpinned external MCP package with the user's API token and exposes broad organizational-context export capability.

Review this before installing. Pin and verify the MCP server package, use a least-privilege UPLO token, restrict export_org_context to users who are allowed to receive broad organizational data, and avoid logging sensitive incident details, credentials, or PII in knowledge-base updates.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
skill.json:25
Finding

Unpinned npm Package Is Downloaded and Executed Automatically

Content
View full analysis

Vulnerability Details

File Location: skill.json:25-40 and README.md:16-21
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

skill.json:25-40:

json
"mcp": {
  "command": "npx",
  "args": [
    "-y",
    "@agentdocs1/mcp-server",
    "--http"
  ],
  "env": {
    "AGENTDOCS_URL": "${config.agentdocs_url}",
    "API_KEY": "${config.api_key}",
    "DEFAULT_PACKS": "data_analytics"
  },
  "transport": "http",
  "url": "${config.agentdocs_url}/mcp"
},

The same unpinned invocation is presented to users in README.md:16-21:

json
{
  "mcpServers": {
    "uplo-data-analytics": {
      "command": "npx",
      "args": ["-y", "@agentdocs1/mcp-server", "--http"],

Technical Analysis

The configuration invokes npx with the -y option and specifies @agentdocs1/mcp-server without an exact version or package-integrity constraint. Consequently, npx may retrieve and execute whichever package version the npm registry currently resolves for the package tag.

This creates a mutable supply-chain execution path: the effective executable can change after this Skill has been reviewed, even when no files in the Skill itself change. The -y option suppresses the normal installation confirmation, making retrieval and execution unattended.

Because the child process receives API_KEY and AGENTDOCS_URL through its environment, a malicious future package release would execute in a context containing the user's UPLO credentials and endpoint information. The reviewed files do not establish that the current package is malicious; the vulnerability is the absence of dependency pinning and integrity controls.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or another part of its release pipeline.
  2. The attacker publishes a malicious version under @agentdocs1/mcp-server that is selecte ...[truncated 1531 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed exact version rather than relying on the registry's current default tag:

    json
    "args": [
      "-y",
      "@agentdocs1/mcp-server@X.Y.Z",
      "--http"
    ]
    
  2. Prefer installing the dependency through a package manifest and committed lockfile rather than downloading it dynamically whenever the MCP server starts.

  3. Verify package integrity using npm lockfile integrity metadata or an equivalent cryptographic verification mechanism.

  4. Remove unattended installation behavior where practical. Avoid npx -y for dynamically resolved packages, or configure npx so it can only use a previously installed and verified local dependency.

  5. Establish a controlled dependency-update process in which new versions are reviewed, tested, scanned, and explicitly approved before deployment.

  6. Run the MCP process in a restricted environment with minimal filesystem access, constrained outbound networking, and no access to unrelated user credentials.

  7. Apply least privilege to the UPLO API token. Limit it to the specific knowledge domains and operations required by this Skill, and avoid granting broad export or write permissions unless necessary.

  8. Document the expected npm registry and package provenance to reduce dependency-confusion and registry-substitution risks.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
- Technical identifiers are your best search terms. Use exact table names (`dim_customers`), column names (`order_status_cd`), dbt model names, and Looker explore names. The extraction engine indexes these precisely.
- When investigating data quality issues, start with `search_with_context` to get the lineage graph, then use `search_knowledge` for specific transformation logic. Working backwards from the symptom to the source is more efficient than searching forward.
- Data governance policies often exist in multiple versions (draft, approved, superseded). Include "approved" or "current" in your query to filter toward the authoritative version.
- The most valuable documentation to contribute back is metric definitions with SQL. When you resolve a metric dispute, log the session and propose an update with the canonical SQL so the next person does not have to repeat the investigation.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · identity-patch.md (reported line 7)May include surrounding context.

md
Expect queries about metric definitions and calculation methodologies, data pipeline architectures and refresh schedules, dashboard specifications and KPI targets, data quality rules and validation procedures, data governance policies and stewardship assignments, data catalog entries and lineage documentation, and reporting distribution schedules and access controls. Use `search_knowledge` for specific metric or pipeline lookups and `search_with_context` when the question requires understanding how a metric is calculated from source data through transformation pipelines to final reporting.

When presenting data analytics information, always cite the specific metric definition, data source, and refresh frequency. For pipelines, include the transformation logic and quality check results. For dashboards, reference the business owner and target audience. Flag any data quality issues, pipeline failures, or metrics with pending definition changes. Raw data access credentials and PII-containing datasets are confidential — respect classification tiers. Identify the responsible data engineer, analytics lead, or data steward via `find_knowledge_owner`.

Respect classification tiers. Never fabricate data-analytics information — only surface what exists in the knowledge base.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises an export_org_context capability as a full organizational context snapshot without any adjacent warning about sensitive data exposure, authorization boundaries, or privacy implications. In a data analytics and governance skill, organizational context may include internal documentation, governance rules, ownership metadata, and potentially confidential business information, so normalizing unrestricted export increases the risk of over-collection and accidental exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This manifest describes broad capabilities such as searching documentation, policies, and reporting standards, but it does not specify when the skill should be invoked or provide narrow trigger phrases. In a manifest file, that lack of trigger scope can make invocation conditions ambiguous and increase the chance of unintended activation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.