Back to skill

Security audit

Uplo Finance

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for finance knowledge search, but it automatically runs an unpinned third-party npm MCP server while passing a sensitive finance API token, which needs review before installation.

Review this before installing in a finance environment. Pin and verify the MCP package version, use a dedicated least-privilege UPLO token, protect and rotate the API key, restrict export_org_context to approved users or workflows, and run the server with limited filesystem and network access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
skill.json:27
Finding

Automatic Execution of an Unpinned Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: skill.json:27-31
Additional Location: README.md:21-22
Vulnerability Type: Unpinned third-party dependency executed automatically through npx -y
Risk Level: High

Vulnerable Code

skill.json:27-31:

json
"command": "npx",
"args": [
  "-y",
  "@agentdocs1/mcp-server",
  "--http"
],

The documented installation configuration contains the same behavior at README.md:21-22:

json
"command": "npx",
"args": ["-y", "@agentdocs1/mcp-server", "--http"],

Technical Analysis

The Skill starts the third-party npm package @agentdocs1/mcp-server through npx without specifying an exact version or verifying an integrity hash. The -y option suppresses the package installation confirmation. Consequently, startup may download and execute whichever package version the npm registry resolves at that time.

This creates a supply-chain trust boundary in which the effective executable code can change after the Skill has been reviewed. If the package publisher account, package repository, release process, or registry distribution channel is compromised, a malicious release could execute locally without requiring further approval.

The MCP process receives the configured API_KEY through its environment and communicates with the configured UPLO endpoint. Code running inside the dependency can therefore potentially read that credential and use the operating-system and network permissions inherited from the agent process.

No evidence was found that the currently referenced package is malicious. The vulnerability is the unsafe, mutable, and confirmation-free dependency execution mechanism.

Attack Path

  1. An attacker compromises the npm publisher account, package build pipeline, source repository, or another part of the distribution chain for @agentdocs1/mcp-server.
  2. The attacker publishes a malicious package version under the legitim ...[truncated 1662 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package to an audited exact version, for example:

    json
    "args": [
      "-y",
      "@agentdocs1/mcp-server@1.2.3",
      "--http"
    ]
    

    Replace the example version with a release that has been independently reviewed.

  2. Prefer installing dependencies through a committed lockfile rather than resolving them dynamically whenever the Skill starts.

  3. Verify package integrity using npm lockfile integrity metadata, trusted checksums, signed provenance, or an internally approved package mirror.

  4. Remove automatic -y installation where operationally possible. Installation and security review should occur as an explicit deployment step rather than during normal Skill execution.

  5. Run the MCP server in a restricted environment with:

    • A dedicated, unprivileged operating-system identity.
    • Read-only or narrowly scoped filesystem access.
    • An outbound network allowlist limited to the required UPLO endpoint and package infrastructure used during controlled installation.
    • No access to unrelated user credentials or agent secrets.
  6. Issue an API token dedicated to this Skill and restrict it to the minimum required financial datasets, actions, tenant, and classification tiers.

  7. Ensure the MCP package receives only required environment variables. Avoid exposing unrelated secrets to the child process.

  8. Monitor dependency ownership, release provenance, vulnerability advisories, and unexpected package updates. Re-review the dependency before changing the pinned version.

  9. Update the README.md example to use the same pinned and verified deployment method so users do not reproduce the unsafe configuration.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown advertises searching financial statements, audit findings, tax documents, and treasury records, which are likely sensitive, but it provides no caution about handling confidential data or access implications. For markdown files, this qualifies as a missing warning because the described behavior could affect user data and privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README instructs users to configure a long-lived API key and advertises capabilities such as full organizational context export without any accompanying warning about secret handling, scope restriction, or export sensitivity. In a finance skill, this combination increases the risk of accidental credential exposure, over-privileged deployment, and broad data exfiltration from highly sensitive organizational records.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.