T08 · Insecure Dependencies
- Location
skill.json:27- Finding
Unpinned Third-Party MCP Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is for media knowledge search, but it grants broad organizational data access and runs an unpinned external MCP package with credentials.
Review this skill before installing. Use only with a trusted UPLO/AgentDocs endpoint, a narrowly scoped and rotatable API token, and users authorized to access media strategy, licensing, budget, and organization-wide context. Pin or otherwise verify the MCP server package before running it, and avoid automatic organizational exports or negotiation logging unless your organization has explicit approval, redaction, retention, and deletion controls.
skill.json:27Unpinned Third-Party MCP Package Is Automatically Downloaded and Executed
SKILL.md:28Session Initialization Automatically Retrieves Sensitive Identity and Strategy Data
SKILL.md:50Project-Specific Workflow Exports a Full Organizational Context Snapshot
SKILL.md:78Blanket Conversation Logging Instruction Can Persist Confidential Negotiation Data
This is a markdown file, so missing-warning review applies to described behaviors that could affect privacy or system integrity. The tool description 'Full organizational context snapshot' suggests broad access to potentially sensitive internal data, but the README provides no caution, scope limitation, or privacy warning to users.
The manifest requires a secret API key and sends it to a remote MCP endpoint over HTTP transport, but it provides no explicit user-facing disclosure about what data will be sent, what remote service will receive it, or the trust implications of connecting an agent to an external system. Even if the example URL is HTTPS, the skill is designed for remote network access and credential use, which can expose sensitive organizational content, licensing records, and analytics if users configure an untrusted or incorrect endpoint.
No suspicious patterns detected.