Back to skill

Security audit

Uplo Education

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for education knowledge search, but it automatically runs an unpinned npm MCP server while passing a sensitive UPLO API token.

Install only if you trust UPLO and the npm package source, and prefer a pinned, reviewed MCP server version. Use a least-privilege UPLO token, restrict it to the education datasets and operations the user needs, and confirm authorization before exporting organizational context or querying data that could include student-identifiable information.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
skill.json:27
Finding

Unpinned npm Package Is Automatically Retrieved and Executed

Content
View full analysis
Remediation
View remediation
", "--http" ] ``` 2. Prefer installing dependencies during a controlled build phase using a committed lockfile and integrity-verified package metadata. Do not dynamically download executable packages when the Skill starts. 3. Remove `-y` where interactive approval is appropriate, although removing it alone does not address mutable dependency resolution. 4. Verify package provenance through registry signatures, trusted publishing, checksums, or an internally controlled package mirror. 5. Pin and audit transitive dependencies. Add automated vulnerability and dependency-drift scanning to the release process. 6. Run the MCP server in a restricted container or sandbox with: - A non-privileged operating-system account. - Read-only filesystem access except for explicitly required paths. - A minimal environment containing only required secrets. - Restricted outbound network access. - Resource limits and no access to host administration interfaces. 7. Scope the UPLO API token to the minimum required operations and institutional datasets. Establish rotation and revocation procedures in case the runtime dependency is compromised. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is described as searching curriculum documents and student records frameworks, which indicates handling potentially sensitive educational data. The README does not include any user-facing warning about privacy, data sensitivity, or appropriate authorization when using these capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The export_org_context tool implies bulk export of organizational knowledge, which can materially affect privacy and system/data integrity if used improperly. The README lists the capability but provides no warning about sensitivity, access controls, or the need to confirm authorization before exporting data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.