T08 · Insecure Dependencies
- Location
skill.json:25- Finding
Unpinned Third-Party Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears purpose-built for DevOps knowledge search, but it uses an unpinned runtime MCP package and exposes broad organizational export capability that need review before installation.
Install only if you trust the UPLO service and the npm package source, and prefer a pinned or internally mirrored MCP server version. Use a narrowly scoped UPLO token, restrict who can call full organizational exports, and confirm that classification, auditing, and redaction controls are enforced server-side before enabling `export_org_context`.
skill.json:25Unpinned Third-Party Package Is Automatically Downloaded and Executed
SKILL.md:78Organization-Wide Context Export Exceeds Least-Privilege Requirements
The README advertises an export_org_context capability as a full organizational context snapshot without any accompanying warning about sensitive data exposure, access controls, or least-privilege expectations. In a DevOps and incident-response knowledge tool, that context likely includes internal infrastructure, runbooks, ownership data, and operational procedures, making accidental overexposure materially risky.
The skill explicitly instructs users to invoke export_org_context during infrastructure migration planning without any warning, scoping guidance, or mention of sensitivity controls. In a DevOps knowledge skill, exported organizational context may include system dependencies, architecture details, ownership mappings, change windows, or other operationally sensitive data, so encouraging export by default increases the risk of oversharing or exfiltration.
This manifest file describes the skill's purpose in broad terms but provides no explicit trigger phrases, invocation scope, or exclusion conditions. In a manifest, that lack of specificity can make activation behavior ambiguous and increase the chance of unintended invocation.
No suspicious patterns detected.