Back to skill

Security audit

Dropbox Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Dropbox integration, but it gives an agent broad file access and includes risky setup guidance for persistent Dropbox credentials.

Install only if you are comfortable granting an agent access to read and change Dropbox files. Prefer the documented Swift/Keychain OAuth path, avoid the npx-based legacy setup unless you pin and review the package, use narrowly scoped Dropbox credentials, and harden or avoid plaintext rclone token files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
references/mcp-setup.md:13
Finding

Unpinned Third-Party npm Package Is Automatically Downloaded and Executed with Dropbox Credentials

Content
View full analysis

Vulnerability Details

File Location: references/mcp-setup.md:13-18
Vulnerability Type: Insecure third-party dependency execution
Risk Level: High

json
"command": "npx",
"args": ["-y", "dbx-mcp-server"],
"env": {
  "DROPBOX_APP_KEY": "YOUR_APP_KEY",
  "DROPBOX_APP_SECRET": "YOUR_APP_SECRET",
  "DROPBOX_REFRESH_TOKEN": "YOUR_REFRESH_TOKEN"
}

Technical Analysis

The MCP configuration invokes npx -y dbx-mcp-server without specifying an exact package version or validating package integrity. When the MCP client starts the server, npx may resolve, download, and execute the package version currently available from the configured npm registry. The -y option suppresses the normal installation confirmation.

This creates a supply-chain trust boundary that is not controlled by the reviewed artifact. A compromised package release, registry account, registry configuration, or transitive dependency could change the executed code after this skill has been reviewed.

The process is explicitly supplied with the Dropbox application key, application secret, and reusable refresh token. Therefore, any code executed through this dependency can read those values from its environment. The artifact contains no lockfile, integrity hash, vendored source, or implementation code through which the referenced package can be verified.

Attack Path

  1. A user copies the documented MCP configuration into an MCP-capable client.
  2. The client launches npx -y dbx-mcp-server.
  3. npx resolves a mutable package version from the configured npm registry and automatically downloads it if necessary.
  4. A compromised or unexpectedly modified package executes as the user running the MCP client.
  5. The package reads DROPBOX_APP_KEY, DROPBOX_APP_SECRET, and DROPBOX_REFRESH_TOKEN from its process environment.
  6. It can use or disclose those credentials, access Dropbox within the granted scopes, manipulate files, or return deceptive MCP tool results.

Impa

...[truncated 563 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the legacy npm-based setup if the maintained Swift dropbook executable is the intended implementation.
  • Otherwise, pin the package to an exact, reviewed version rather than allowing mutable resolution.
  • Install dependencies separately under a committed lockfile and verify registry provenance and integrity before execution.
  • Avoid npx -y in persistent MCP configurations because it permits unattended package retrieval and execution.
  • Prefer a locally installed executable referenced by an absolute path after its source and release artifacts have been reviewed.
  • Restrict Dropbox application scopes to the minimum required operations.
  • Use isolated, revocable credentials and rotate the refresh token if an untrusted package may have received it.
  • Run the MCP server in a restricted environment with limited filesystem and network access where practical.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:306
Finding

Dropbox Access Token Is Stored in a Plaintext Configuration File Without Enforced Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:306-312
Vulnerability Type: Insecure storage of sensitive credentials
Risk Level: Medium

bash
# Save the token output to config
mkdir -p ~/.config/rclone
cat > ~/.config/rclone/rclone.conf << 'EOF'
[dropbox]
type = dropbox
token = {"access_token":"...paste token here..."}
EOF

Technical Analysis

The documented commands write a Dropbox access token directly to ~/.config/rclone/rclone.conf. They do not create the directory or file with explicit owner-only permissions and do not verify the user's umask.

As a result, the resulting permissions are environment-dependent. Under a permissive umask, another local account or process may be able to read the configuration. The token remains present in plaintext at rest, despite the primary setup elsewhere recommending macOS Keychain-backed credential storage.

The snippet uses a placeholder rather than a real credential, so the artifact does not itself expose a secret. The vulnerability occurs when a user follows the instructions and replaces the placeholder with a valid token.

Attack Path

  1. A user obtains an rclone Dropbox token and follows the documented commands.
  2. The shell creates ~/.config/rclone/rclone.conf according to the user's current umask.
  3. The valid Dropbox token is stored in plaintext in that file.
  4. If permissions allow access, another local user or compromised process reads the configuration.
  5. The attacker extracts the token and submits authenticated Dropbox API requests or configures another rclone client.
  6. The attacker accesses or alters Dropbox resources permitted by the token until it expires or is revoked.

Impact Assessment

Exploitation may grant authenticated Dropbox access within the token's scopes. Potential effects include reading account data, downloading files, uploading or modifying content, and deleting accessible data.

This issue does not independently provide privilege escalation to ...[truncated 196 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer rclone's supported interactive configuration workflow rather than manually constructing a credential-bearing file.
  • Create the configuration directory with owner-only permissions:
bash
install -d -m 700 "$HOME/.config/rclone"
  • Pre-create the configuration file with owner read/write access before writing the token:
bash
install -m 600 /dev/null "$HOME/.config/rclone/rclone.conf"
  • Verify the final permissions with stat or ls -l.
  • Document that users should maintain a restrictive umask, such as 077, while handling credentials.
  • Where supported, use an operating-system credential store or rclone configuration encryption rather than retaining an unprotected plaintext token.
  • Use narrowly scoped and revocable Dropbox credentials.
  • Revoke and rotate any token whose configuration file may have been readable by unauthorized principals.
  • Avoid printing the token in logs, terminal transcripts, command histories, or support output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.json (reported line 39)May include surrounding context.

json
{
        "name": "DROPBOX_ACCESS_TOKEN",
        "required": true,
        "description": "Dropbox access token for API authentication"
      }
    ]
  },

Self-Modification

High
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill exposes a file upload operation with an overwrite option, which can replace existing remote files and cause irreversible data loss or unauthorized modification if invoked incorrectly or through prompt manipulation. In the context of an agent skill that bridges local files and cloud storage, write capabilities are materially more dangerous because they can alter user data outside the immediate session.

Content

Scanner excerpt · SKILL.json (reported line 94)May include surrounding context.

json
"type": "boolean",
            "optional": true,
            "default": false,
            "description": "Overwrite existing file"
          }
        }
      },

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

bash
# Authentication
make login                 # OAuth login with Keychain storage
make logout                # Clear stored tokens

# File operations

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

bash
# Authentication
make login                 # OAuth login with Keychain storage
make logout                # Clear stored tokens

# File operations

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
80% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · SKILL.md (reported line 269)May include surrounding context.

md
| `notConfigured` | Missing env vars | Set DROPBOX_APP_KEY, DROPBOX_APP_SECRET |
| `invalidArguments` | Missing required params | Check tool parameters |
| `notFound` | Path doesn't exist | Use `list_directory` to verify paths |
| `itemNotFound` | No token in Keychain | Run `make login` to authenticate |

## Architecture

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/mcp-setup.md (reported line 36)May include surrounding context.

md
## Troubleshooting

- **Token Expired**: Ensure you are using a *refresh* token, not a short-lived access token.
- **Permission Denied**: Check the scopes in the Dropbox App Console.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest advertises capabilities to upload to Dropbox and download to arbitrary local paths, but it does not include any explicit warning, consent language, or safety constraints around data exfiltration, remote data import, or local file modification. In an agent setting, this increases the risk of a user or model invoking destructive or privacy-impacting file operations without understanding that cloud and local filesystem state may be changed.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill documents writing a Dropbox OAuth token directly into ~/.config/rclone/rclone.conf, which creates persistent local credential storage outside the OS Keychain. If file permissions are weak, the host is shared, or the config is backed up/synced insecurely, the token can be stolen and reused to access the user's Dropbox account.

Content

Scanner excerpt · SKILL.md (reported line 307)May include surrounding context.

md
rclone authorize dropbox

# Save the token output to config
mkdir -p ~/.config/rclone
cat > ~/.config/rclone/rclone.conf << 'EOF'
[dropbox]
type = dropbox

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented rclone sync command is destructive because it deletes destination files that are not present in the source, but the example is presented without an immediate, prominent warning at the point of use. In an agent skill context, users may copy commands verbatim, increasing the risk of accidental data loss on local backups or mounted storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs users to place a Dropbox app secret and refresh token directly into a local MCP configuration file, but provides no warning about protecting those values, excluding the file from version control, or using a safer secret-management mechanism. In an agent setup context, these credentials grant persistent API access to Dropbox and could be exposed through accidental commits, local file disclosure, logs, or shared workstation access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.