Back to skill

Security audit

Uplo Defense

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent defense knowledge tool, but it handles highly sensitive data while running an unpinned npm MCP server with the user's API token.

Install only in an authorized defense environment. Use a narrowly scoped, revocable UPLO token, confirm server-side clearance and need-to-know enforcement, restrict export_org_context to approved users, and prefer a pinned or locally reviewed MCP server package instead of unpinned npx execution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
skill.json:25
Finding

Automatic Execution of an Unpinned Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: skill.json, lines 25–29
Vulnerability Type: Unpinned dependency downloaded and executed automatically
Risk Level: High

Vulnerable Code:

json
"command": "npx",
"args": [
  "-y",
  "@agentdocs1/mcp-server",
  "--http"
],

Technical Analysis

The Skill launches @agentdocs1/mcp-server through npx without specifying an exact package version or integrity digest. The -y option automatically accepts installation prompts, allowing npm to download and execute the package version resolved at runtime.

Consequently, the code executed during future installations can differ from the code that was available when the Skill was audited. The launched package also receives the configured API_KEY and AGENTDOCS_URL environment variables. This creates a supply-chain trust boundary in which a compromised npm package, publishing account, or newly published malicious release could execute arbitrary code and access those credentials.

The audit found no evidence that the current package is malicious. The vulnerability is the unsafe, mutable dependency execution mechanism.

Attack Path

  1. An attacker compromises the npm package, its maintainer account, or its publishing workflow.
  2. The attacker publishes a malicious release under @agentdocs1/mcp-server.
  3. A user installs or starts the Skill after that release becomes the version resolved by npm.
  4. npx -y downloads the package and executes it without an interactive approval step.
  5. The malicious package reads API_KEY, AGENTDOCS_URL, or other data available to the process.
  6. The payload may exfiltrate credentials, access the configured UPLO service, or perform actions with the operating-system privileges of the Agent process.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the account running the Skill. The attacker could potentially:

  • Read the U ...[truncated 509 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @agentdocs1/mcp-server to a reviewed, exact version rather than resolving the latest available release.
  2. Install the dependency through a committed lockfile and use a reproducible installation command such as npm ci.
  3. Verify package provenance, signatures, and integrity hashes before execution.
  4. Remove -y where practical so unexpected installation or version changes require explicit approval.
  5. Prefer a locally installed, reviewed executable over runtime package retrieval.
  6. Run the MCP server in a restricted container or sandbox with minimal filesystem and network access.
  7. Supply a narrowly scoped, revocable API token and rotate it after any suspected dependency compromise.
  8. Monitor package ownership, release history, and security advisories, and require dependency review before upgrades.

T08 · Insecure Dependencies

Error
Location
README.md:23
Finding

Documentation Recommends Unpinned Runtime Package Execution

Content
View full analysis

Vulnerability Details

File Location: README.md, line 23
Vulnerability Type: Unsafe dependency installation configuration
Risk Level: High

Vulnerable Code:

json
{
  "mcpServers": {
    "uplo-defense": {
      "command": "npx",
      "args": ["-y", "@agentdocs1/mcp-server", "--http"],
      "env": {
        "AGENTDOCS_URL": "https://your-instance.uplo.ai",
        "API_KEY": "your-api-key",
        "DEFAULT_PACKS": "defense"
      }
    }
  }
}

Technical Analysis

The documented Claude Desktop configuration instructs users to execute an unversioned npm package using npx -y. This reproduces the insecure dependency behavior in downstream installations, even if the packaged Skill configuration is later corrected.

Because no version or integrity constraint is supplied, each installation may execute a different release. The package is also started with an API credential in its environment. A compromised release would therefore execute inside the desktop Agent environment with access to the configured token and all other resources available to that process.

No hardcoded live credential appears in this example; your-api-key is a placeholder. The confirmed issue is the recommendation to retrieve and execute mutable third-party code automatically.

Attack Path

  1. An attacker publishes a malicious release after compromising the package or its publication channel.
  2. A user copies the configuration from the README into Claude Desktop.
  3. On startup, npx -y resolves, downloads, and executes the attacker-controlled release.
  4. The package obtains the real API_KEY and UPLO endpoint configured by the user.
  5. The package exfiltrates the credential, accesses permitted organizational data, alters MCP behavior, or executes other code with the desktop process's privileges.

Impact Assessment

Exploitation could compromise users who follow the installation documentation ...[truncated 406 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the unversioned package reference with an exact, audited release.
  2. Document a lockfile-based installation workflow rather than runtime retrieval through npx -y.
  3. Include package integrity and provenance verification instructions.
  4. Advise users to run the MCP server in an isolated environment with least-privilege filesystem and network permissions.
  5. Require narrowly scoped API tokens and document token rotation and revocation procedures.
  6. Keep the README configuration synchronized with the hardened configuration in skill.json.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly markets search over mission documentation, logistics records, personnel data, and ITAR-controlled information, but provides no accompanying warning about authorization boundaries, export restrictions, privacy obligations, or secure handling. In a defense context, normalizing access to highly sensitive datasets without visible safeguards can encourage unsafe deployment and misuse, especially by users who treat the README as operational guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documenting an export_org_context tool as a 'Full organizational context snapshot' without any warning or limitation is risky because it implies bulk extraction of potentially sensitive organizational knowledge. In this defense-oriented skill, such an export could include mission, personnel, logistics, or regulated information, making misuse or overbroad access especially damaging.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.