Back to skill

Security audit

Uplo Media

Security checks for vulnerabilities and agentic risk

Overview

This skill is for media knowledge search, but it grants broad organizational data access and runs an unpinned external MCP package with credentials.

Review this skill before installing. Use only with a trusted UPLO/AgentDocs endpoint, a narrowly scoped and rotatable API token, and users authorized to access media strategy, licensing, budget, and organization-wide context. Pin or otherwise verify the MCP server package before running it, and avoid automatic organizational exports or negotiation logging unless your organization has explicit approval, redaction, retention, and deletion controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
skill.json:27
Finding

Unpinned Third-Party MCP Package Is Automatically Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:28
Finding

Session Initialization Automatically Retrieves Sensitive Identity and Strategy Data

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:50
Finding

Project-Specific Workflow Exports a Full Organizational Context Snapshot

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:78
Finding

Blanket Conversation Logging Instruction Can Persist Confidential Negotiation Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a markdown file, so missing-warning review applies to described behaviors that could affect privacy or system integrity. The tool description 'Full organizational context snapshot' suggests broad access to potentially sensitive internal data, but the README provides no caution, scope limitation, or privacy warning to users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest requires a secret API key and sends it to a remote MCP endpoint over HTTP transport, but it provides no explicit user-facing disclosure about what data will be sent, what remote service will receive it, or the trust implications of connecting an agent to an external system. Even if the example URL is HTTPS, the skill is designed for remote network access and credential use, which can expose sensitive organizational content, licensing records, and analytics if users configure an untrusted or incorrect endpoint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.