Back to skill

Security audit

ViBo MCP

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local memory MCP skill, with the main caution being that users must trust and safely install an external pinned npm package.

Install only if you are comfortable trusting the pinned external npm package and giving it access to a ViBo license key plus its local memory store. Prefer the controlled pinned install, avoid running it as administrator/root, restrict filesystem access to its storage directory where possible, and review the package/source before storing sensitive facts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:7
Finding

Unverified Third-Party npm Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:40-70 and INSTALL.md:7-21
Vulnerability Type: Third-party supply-chain exposure through npm installation and automatic execution
Risk Level: Medium

The documentation directs users to retrieve and execute the external npm package @vibo-dev/vibo-mcp@0.2.5. The implementation of that package is not included in the audited project, so its lifecycle scripts, transitive dependencies, network behavior, local file access, and handling of VIBO_API_KEY cannot be independently verified from the available files.

Complete relevant installation instructions from INSTALL.md:

bash
# 1) verify the exact release before installing
npm view @vibo-dev/vibo-mcp@0.2.5 version dist.integrity

# 2) controlled global install (done once, not re-resolved on every start)
npm install -g @vibo-dev/vibo-mcp@0.2.5

# 3) confirm
vibo-mcp --version

The alternative execution path is:

bash
npx -y @vibo-dev/vibo-mcp@0.2.5

The corresponding instructions in SKILL.md include:

bash
# 1) verify the version you are about to install
npm view @vibo-dev/vibo-mcp@0.2.5 version dist.integrity

# 2) controlled global install (lifecycle scripts run once, under your user)
npm install -g @vibo-dev/vibo-mcp@0.2.5

# 3) confirm the installed version
vibo-mcp --version
bash
npm ls -g @vibo-dev/vibo-mcp

Technical Analysis

Version pinning reduces unintended upgrade drift but does not establish that the pinned artifact is trustworthy. The command npm view ... dist.integrity only displays registry-provided integrity metadata; the documented process does not compare the package against a digest obtained through an independent, trusted channel. Similarly, npm ls reports the installed dependency tree but does not independently verify the provenance or security of the installed code.

A global npm installation can execute package lifecycle scrip ...[truncated 2179 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include the reviewed MCP implementation and dependency lockfile in the project, or link each distributed release to publicly auditable source code and a reproducible build process.
  2. Publish a trusted SHA-512 digest for the exact package tarball through a channel independent of the npm registry, and document an explicit download-and-compare verification procedure.
  3. Avoid presenting npm view ... dist.integrity or npm ls as independent integrity verification because both rely on npm metadata or installed package state.
  4. Prefer downloading and verifying the package once, then running a locally controlled binary rather than using npx -y.
  5. Disable lifecycle scripts during installation with --ignore-scripts unless the package documents why they are required and those scripts have been reviewed.
  6. Install the package in a dedicated, non-privileged environment rather than globally. Never run the installation as root or administrator.
  7. Execute the MCP server in a sandbox with filesystem access restricted to its designated storage directory and network access restricted to the documented license endpoint.
  8. Audit and lock all transitive dependencies, generate a software bill of materials, and scan releases for known vulnerabilities before promotion.
  9. Reconcile the Skill metadata version 0.2.6 with the instructed package version 0.2.5 so users can clearly determine which implementation was reviewed.
  10. Document key rotation and incident-response procedures in case VIBO_API_KEY is exposed through a compromised package.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

text

New releases are reviewed and tested before they are promoted — do not
switch to a newer version without checking its changelog. Run the MCP
server with least-privileged local access (its own storage path only).

## Tools

Static analysis

No suspicious patterns detected.