Back to skill

Security audit

MachineCommander

Security checks for vulnerabilities and agentic risk

Overview

This query skill also documents an unrestricted machine-management command, so users should review it before installing despite no evidence of hidden code or persistence.

Install only if the connected MachineCommander MCP service is trusted, access-controlled, and configured so this skill cannot issue real equipment commands without explicit human authorization. Treat location, tenant, project, alert, and trajectory data as sensitive operational information.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:18
Finding

Unrestricted Operational Command Capability

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18–21
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: High

bash
### Send instructions

mcporter call MachineCommander manage_construction_machines 'order=your instruction'

The snippet above is an English translation of the documented command while preserving its original semantics.

Technical Analysis

The skill documents a call to the manage_construction_machines endpoint that accepts an arbitrary natural-language instruction. No authorization check, target restriction, command allowlist, confirmation step, dry-run preview, or separation between read-only and state-changing operations is specified.

This capability conflicts with the skill's primarily query-oriented purpose. It expands the Agent's effective permissions from retrieving equipment information to potentially controlling or changing the state of connected construction machinery. Because the MCP service implementation is external to the audited project, the exact supported commands and their effects cannot be verified from the available files.

Attack Path

  1. A malicious user, compromised upstream workflow, or prompt-injected context supplies an operational instruction involving connected machinery.
  2. The Agent interprets the instruction as eligible for the documented management workflow.
  3. The Agent invokes MachineCommander manage_construction_machines, placing the untrusted instruction in the order argument.
  4. No skill-level confirmation, authorization, target validation, or command restriction prevents submission.
  5. If the external MCP service accepts and executes the instruction, the attacker may cause an unauthorized state-changing action.

Exploitation ultimately depends on the permissions and command behavior of the externally configured MachineCommander service.

Impact Assessment

Successful exploitation could al ...[truncated 594 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove manage_construction_machines from this query-focused skill and expose it only through a separate, explicitly privileged management skill.
  2. Require explicit user confirmation immediately before every state-changing operation, including a preview of the target machines and intended effects.
  3. Implement a strict allowlist of supported operations and reject unrestricted natural-language management instructions.
  4. Validate machine identifiers, tenant ownership, project scope, and requested actions before invoking the MCP service.
  5. Use a dedicated least-privilege service identity for queries. Management operations should require a separately authorized identity.
  6. Add role-based access control and enforce authorization server-side rather than relying solely on Agent instructions.
  7. Provide a dry-run mode that resolves and displays the proposed action without executing it.
  8. Reject management instructions originating from retrieved documents, tool output, or other untrusted indirect content.
  9. Record the requesting user, resolved targets, operation, confirmation, result, and timestamp in tamper-resistant audit logs.
  10. Define emergency controls, rate limits, and safe failure behavior for commands that could affect machinery operation.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises access to real-time GPS location, status, project, and tenant data, which are operationally sensitive and potentially privacy-relevant. Without any warning, minimization guidance, or access constraints, the skill could facilitate unnecessary exposure of fleet movements, customer/project associations, and other sensitive operational intelligence.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata and description frame this as a query skill, but the documentation also exposes manage_construction_machines, which appears to issue operational commands to real machinery. That mismatch is dangerous because users or downstream agents may invoke a control-capable tool under the assumption that the skill is read-only, creating a pathway for unauthorized or unsafe physical actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file states that all queries use get_construction_machines_data, yet it also documents a separate command path for machine management. This inconsistency can mislead an agent or operator about the available side-effecting functionality, increasing the risk of accidental command execution or bypass of expected safety review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Documenting a machine-management command without any warning about real-world side effects normalizes the use of an action-capable interface in a safety-sensitive context. In a construction and marine operations environment, poorly constrained command execution could disrupt operations, damage equipment, or create physical safety hazards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
61% confidence
Finding

The natural-language description is written entirely in Chinese and states that this skill must be used for certain user questions. While not inherently unsafe, it does not offer any language or locale choice or note that responses can adapt to user preference, which may conflict with language/locale flexibility policies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.