Back to skill

Security audit

Uplo Legal

Security checks for vulnerabilities and agentic risk

Overview

This legal knowledge skill is coherent, but it needs Review because it combines sensitive legal-data access with under-scoped export/logging behavior and an unpinned npm server install that receives the API token.

Review before installing. Use a least-privilege UPLO token, confirm whether full org-context export is allowed for your legal data, require consent or disable conversation logging for privileged matters, and prefer a pinned or otherwise verified MCP server package before running it with real credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
skill.json:21
Finding

Unpinned npm Package Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: skill.json:21-28; also documented in README.md:16-26
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: High

Vulnerable Code

skill.json:21-28:

json
"mcp": {
  "command": "npx",
  "args": ["-y", "@agentdocs1/mcp-server", "--http"],
  "env": {
    "AGENTDOCS_URL": "${config.agentdocs_url}",
    "API_KEY": "${config.api_key}",
    "DEFAULT_PACKS": "legal"
  },

README.md:16-26:

json
{
  "mcpServers": {
    "uplo-legal": {
      "command": "npx",
      "args": ["-y", "@agentdocs1/mcp-server", "--http"],
      "env": {
        "AGENTDOCS_URL": "https://your-instance.uplo.ai",
        "API_KEY": "your-api-key",
        "DEFAULT_PACKS": "legal"
      }
    }

Technical Analysis

The configuration invokes npx with the -y option and a package name that has no exact version or integrity constraint. Consequently, npm can retrieve and execute the package version currently resolved from the configured registry without interactive confirmation.

This creates a supply-chain trust boundary outside the audited project. The effective executable can change after this skill has been reviewed. A compromised maintainer account, malicious package release, registry compromise, or unsafe registry substitution could cause attacker-controlled JavaScript to execute when the MCP server starts.

The spawned package receives API_KEY and AGENTDOCS_URL through its environment. Therefore, dependency compromise could expose the UPLO credential and organization endpoint directly. The process also executes with the operating-system privileges and environmental access granted to the agent runtime.

Attack Path

  1. An attacker compromises the @agentdocs1/mcp-server publishing account, its build pipeline, or a registry used by the deployment.
  2. The attacker publishes a malicious version under the same package ...[truncated 1447 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed, immutable version, for example:

    json
    "args": ["-y", "@agentdocs1/mcp-server@1.2.3", "--http"]
    
  2. Prefer a controlled installation step using a committed lockfile and npm ci rather than downloading code dynamically whenever the skill starts.

  3. Verify package integrity with lockfile integrity hashes, provenance attestations, and trusted-registry enforcement.

  4. Disable registry overrides and prevent fallback to untrusted package registries in the execution environment.

  5. Review the package contents and transitive dependency tree before upgrading the pinned version.

  6. Run the MCP server in a restricted container or sandbox with minimal filesystem permissions, limited outbound network access, and no unrelated environment variables.

  7. Issue a narrowly scoped UPLO token that permits only the operations required by this skill. Avoid granting administrative, cross-tenant, or unrestricted export privileges.

  8. Rotate the API token promptly if an untrusted dependency version may already have executed.

  9. Monitor package-version changes, token use, unusual organization-context exports, and outbound network connections from the MCP process.

  10. Update the installation example in README.md:16-26 so users are not instructed to deploy the unpinned command.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises an export_org_context capability that appears to provide a full organizational context snapshot, but it gives no warning about sensitivity, least-privilege expectations, or privacy controls. In a legal knowledge-management skill, this context likely includes contracts, compliance records, policy documents, and other confidential material, so normalizing bulk export without security guidance increases the risk of oversharing or unsafe deployment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s stated purpose is legal knowledge search and extraction, but it also instructs the agent to log conversation summaries, topics, and tool usage back into the system. In a legal-domain skill, conversations may contain privileged, sensitive, or regulated information, so implicit write-back behavior expands the data flow beyond user expectations and can create confidentiality, retention, and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The session-end instruction captures and persists conversation-derived data without any user-facing notice or consent mechanism. Because this skill operates on legal and compliance material, the logged summary and topics could reveal sensitive matters, internal investigations, contract details, or attorney-client-related context, making undisclosed persistence more dangerous in this domain.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.