Back to skill

Security audit

Uplo Devops

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-built for DevOps knowledge search, but it uses an unpinned runtime MCP package and exposes broad organizational export capability that need review before installation.

Install only if you trust the UPLO service and the npm package source, and prefer a pinned or internally mirrored MCP server version. Use a narrowly scoped UPLO token, restrict who can call full organizational exports, and confirm that classification, auditing, and redaction controls are enforced server-side before enabling `export_org_context`.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
skill.json:25
Finding

Unpinned Third-Party Package Is Automatically Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:78
Finding

Organization-Wide Context Export Exceeds Least-Privilege Requirements

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README advertises an export_org_context capability as a full organizational context snapshot without any accompanying warning about sensitive data exposure, access controls, or least-privilege expectations. In a DevOps and incident-response knowledge tool, that context likely includes internal infrastructure, runbooks, ownership data, and operational procedures, making accidental overexposure materially risky.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs users to invoke export_org_context during infrastructure migration planning without any warning, scoping guidance, or mention of sensitivity controls. In a DevOps knowledge skill, exported organizational context may include system dependencies, architecture details, ownership mappings, change windows, or other operationally sensitive data, so encouraging export by default increases the risk of oversharing or exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest file describes the skill's purpose in broad terms but provides no explicit trigger phrases, invocation scope, or exclusion conditions. In a manifest, that lack of specificity can make activation behavior ambiguous and increase the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.