T08 · Insecure Dependencies
- Location
skill.json:26- Finding
Unpinned npm Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This government knowledge skill is coherent, but it combines sensitive agency-context export, API-token use, and unpinned runtime package execution that users should review carefully.
Install only in a controlled environment. Pin and review the MCP server package before use, run it with minimal filesystem and network access, use a least-privilege UPLO token, and restrict full organizational exports to authorized users with appropriate classification handling and review.
skill.json:26Unpinned npm Package Is Automatically Downloaded and Executed
The README advertises an export_org_context tool as a "Full organizational context snapshot" without any warning about access controls, least-privilege expectations, or the sensitivity of the exported data. In a government knowledge-management context, organizational context may include internal relationships, directives, owners, and restricted information, so normalizing broad export functionality without caution can encourage unsafe deployment and overbroad access.
The skill explicitly promotes exporting the complete agency knowledge map, including mission, structure, personnel, systems, goals, and active directives, but does not provide a strong user-facing warning, scoping requirement, or minimization guidance. In a government environment, that breadth can expose sensitive internal organizational, operational, or pre-decisional information and materially increase the risk of over-disclosure even if the user is otherwise authorized.
This manifest defines a secret API token and injects it into the MCP process environment and HTTP configuration, but the description does not warn users that credentials will be used and transmitted to an external service endpoint. For manifest files, this falls under missing user warnings because the skill handles sensitive credentials and network communication without visible disclosure in the skill description.
No suspicious patterns detected.