T08 · Insecure Dependencies
- Location
skill.json:28- Finding
Unpinned npm Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is for legitimate knowledge-management search, but it enables broad organizational export and runs an unpinned npm MCP server with an API token.
Install only if you trust UPLO and the npm MCP package source, can use a narrowly scoped UPLO token, and are comfortable with the agent accessing sensitive organizational knowledge. Prefer pinning the MCP server version, protecting and rotating the API key, and requiring explicit approval before any full organizational context export.
skill.json:28Unpinned npm Package Is Automatically Downloaded and Executed
SKILL.md:65Full Organizational Context Export Is Enabled Beyond Routine Search Requirements
The listed 'When to Use' examples are extremely broad and overlap with many ordinary organizational requests, which can cause the skill to be invoked for high-sensitivity knowledge discovery without clear scoping, authorization, or least-privilege guidance. In this KM context, the danger is elevated because the skill explicitly targets expertise directories, retention strategy, tool adoption metrics, and records disposition information that may expose sensitive internal structure and governance data.
The skill recommends using export_org_context as a 'best friend' and says the full organizational context export reveals the state of institutional knowledge, but it provides no warning, gating, or minimization guidance for what is likely a highly sensitive bulk-export capability. In a knowledge management skill, this is especially dangerous because aggregated exports can expose expertise maps, knowledge gaps, operational dependencies, and restricted strategic documents at a scale far beyond what is needed for most user tasks.
This markdown file instructs users to set an API_KEY environment variable for the MCP server, which is a sensitive credential. The README does not include any warning about protecting the key, avoiding accidental disclosure, or understanding that the skill will use authenticated access to organizational data.
No suspicious patterns detected.