Back to skill

Security audit

Uplo Enterprise It

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for enterprise IT search, but it combines broad organizational data export with automatic execution of an unpinned external MCP package.

Install only if you trust the UPLO service and the external MCP package supply chain. Use a dedicated least-privilege UPLO token, prefer a pinned reviewed package version, and require human approval before using export_org_context because it may load broad infrastructure, security, and organizational information into the agent context.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
skill.json:30
Finding

Automatic Execution of an Unpinned Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: skill.json:30-35
Vulnerability Type: Supply-chain risk through unpinned dependency execution
Risk Level: High

Complete Code Snippet:

json
"mcp": {
  "command": "npx",
  "args": [
    "-y",
    "@agentdocs1/mcp-server",
    "--http"
  ],

The same insecure installation pattern is also documented in README.md:21-24:

json
"command": "npx",
"args": ["-y", "@agentdocs1/mcp-server", "--http"],

Technical Analysis

The skill invokes npx with the -y option to download and execute @agentdocs1/mcp-server automatically. The package reference does not specify an exact version or integrity hash. Consequently, the code executed when the skill starts can change after this skill package has been reviewed.

The -y option suppresses the package-installation confirmation, eliminating an opportunity for the user to review the resolved package and version. If the publisher account, registry, package, or release process is compromised, a malicious release could be selected and executed without any corresponding modification to this repository.

Attack Path

  1. An attacker compromises the package publisher, publication credentials, registry delivery path, or another relevant supply-chain component.
  2. The attacker publishes a malicious version under @agentdocs1/mcp-server.
  3. A user installs or starts this skill.
  4. npx -y resolves the unpinned package reference and downloads the currently selected registry version.
  5. The malicious package executes with the operating-system privileges and environment available to the agent process.
  6. The package can attempt to read accessible files and environment variables, including the configured UPLO API credential, and communicate with network destinations allowed by the host.

Impact Assessment

Successful exploitation could result in arbitrary code execution under the account running ...[truncated 584 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed, exact version, such as @agentdocs1/mcp-server@X.Y.Z; do not use a range or floating tag.
  2. Verify the package artifact with a trusted lockfile, registry integrity metadata, checksum, or signature.
  3. Remove automatic confirmation where practical and require explicit approval before installing a previously unavailable package.
  4. Prefer installing dependencies during a controlled build process rather than downloading executable code when the skill starts.
  5. Monitor the package version and provenance and require security review before upgrades.
  6. Run the MCP server in a sandbox or container with a read-only filesystem, minimal environment exposure, restricted outbound networking, and a dedicated low-privilege account.
  7. Provide a narrowly scoped, short-lived API token and rotate it if dependency compromise is suspected.

other

Warning
Location
SKILL.md:54
Finding

Unnecessarily Broad Export of Organizational Context

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:54-58
Vulnerability Type: Excessive sensitive-data retrieval
Risk Level: Medium

Complete Code Snippet:

text
search_knowledge query="encryption at rest and in transit standards for PII data stores"
text
export_org_context
text
Review the exported context to identify gaps in documented controls before the auditor arrives.

The broad scope of the operation is explicitly described at SKILL.md:69:

text
**export_org_context** — Full organizational snapshot. Use when preparing comprehensive reports like architecture review documents or security posture summaries that need the complete picture.

Technical Analysis

The workflow instructs the agent to retrieve a full organizational snapshot while preparing compliance or security reports. This is broader than querying only the controls and systems necessary for the current request. Enterprise IT context may contain sensitive infrastructure descriptions, security controls, incident information, architecture records, ownership details, or other restricted material.

Classification enforcement by the remote service may limit what is returned, but it does not eliminate the least-privilege issue: all information available to the supplied token may be loaded into the agent context even when only a small subset is needed. Retrieved information may subsequently appear in model context, telemetry, logs, generated reports, or downstream integrations.

Attack Path

  1. A user or untrusted request asks the agent to prepare a broad compliance, architecture, or security report.
  2. Following the documented workflow, the agent invokes export_org_context.
  3. The UPLO service returns the full organizational snapshot accessible to the configured API token.
  4. Unrelated sensitive information is placed into the agent's processing context.
  5. That information may be disclosed through ...[truncated 872 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace full-context export with narrowly scoped search_knowledge or search_with_context queries targeted to the requested systems, controls, and reporting period.
  2. Require explicit user confirmation before invoking export_org_context, clearly identifying the scope and sensitivity of the data to be retrieved.
  3. Enforce purpose, environment, system, and classification filters on exports.
  4. Use a dedicated API token with only the minimum datasets and classification tiers needed for the task.
  5. Redact credentials, secrets, penetration-test details, sensitive topology, and unrelated personal or organizational information before content enters the model context.
  6. Limit logging and retention of exported data and ensure downstream report-generation systems apply equivalent access controls.
  7. Record and audit bulk-export operations, including requesting identity, purpose, data scope, and recipients.
  8. Reserve full exports for exceptional, authorized workflows rather than recommending them as the default approach for comprehensive reports.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises an export_org_context capability as a full organizational context snapshot without any accompanying warning about sensitivity, least-privilege expectations, or privacy/security controls. In an enterprise IT and cybersecurity skill, this is especially risky because users may expose infrastructure, security, architecture, and internal operational knowledge at broad scope, increasing the chance of accidental over-disclosure or misuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is ներկայացված as a unified search/intelligence interface, but it exposes an export_org_context capability that can enable bulk extraction of organizational knowledge beyond normal search use. In an enterprise IT and security context, that mismatch increases the risk of overbroad data access, inadvertent exfiltration, or abuse by downstream agents that assume the skill is read-only/search-limited.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.