Back to skill

Security audit

test202603131551

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent commodity quote helper, but its setup asks users to run mutable remote packages and store an API key in persistent agent configs, so it should be reviewed carefully before installation.

Install only if you trust OctagonAI and the npm/package sources involved. Prefer pinning octagon-mcp and installer versions, review package provenance before running them, avoid curl-to-bash setup where possible, store the Octagon API key in a protected secret mechanism rather than shared config files, and treat the commodity analysis as informational rather than trading advice.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/mcp-setup.md:18
Finding

Unverified Remote Homebrew Installer Is Executed Directly by Bash

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/mcp-setup.md:55
Finding

Unpinned npm Packages Are Automatically Downloaded and Executed

Content
View full analysis
npx -y octagon-mcp ``` Claude Desktop configuration: ```json { "mcpServers": { "octagon-mcp-server": { "command": "npx", "args": ["-y", "octagon-mcp@latest"], "env": { "OCTAGON_API_KEY": "YOUR_API_KEY_HERE" } } } } ``` Windsurf configuration: ```json { "mcpServers": { "octagon-mcp-server": { "command": "npx", "args": ["-y", "octagon-mcp@latest"], "env": { "OCTAGON_API_KEY": "YOUR_API_KEY_HERE" } } } } ``` The README also recommends mutable package execution: ```bash npx skills add OctagonAI/skills --skill commodities-quote ``` ```bash bunx skills add OctagonAI/skills --skill commodities-quote ``` ```bash pnpm dlx skills add OctagonAI/skills --skill commodities-quote ``` ### Technical Analysis The MCP server is launched through `npx -y` and, in two configurations, explicitly through `octagon-mcp@latest`. These forms download and execute registry-controlled content without an exact version, lockfile, or recorded integrity value. The `-y` option suppresses interactive confirmation. Because these commands are placed in persistent MCP configuration, the package may be resolved again during later agent launches. A future release can therefore execute without a corresponding review of this Skill. npm lifecycle scripts and the MCP server process execute as local code, not merely as passive data dependencies. The README’s `npx`, `bunx`, and `pnpm dlx` installation commands introduce similar mutable dependency resolution for the Skill installer. ### Attack Path 1. An attacker compromises the npm package, a maintainer or publisher account, or a transitive dependency. ...[truncated 945 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/mcp-setup.md:55
Finding

Octagon API Key Is Stored in Plaintext MCP Configuration

Content
View full analysis
npx -y octagon-mcp ``` Windows configuration: ```text cmd /c "set OCTAGON_API_KEY= && npx -y octagon-mcp" ``` Claude Desktop and Windsurf configuration: ```json "env": { "OCTAGON_API_KEY": "YOUR_API_KEY_HERE" } ``` ### Technical Analysis Users are instructed to replace the placeholder with their actual API key in a persistent MCP command or JSON configuration file. This stores the credential as plaintext and may additionally expose it through configuration backups, support archives, screenshots, accidental source-control commits, or local process inspection. The instructions do not recommend a credential manager, restrictive file permissions, diagnostic redaction, key scoping, or key rotation. The Windows command also places the credential directly in a command string. This issue does not demonstrate that the Skill itself transmits the key to an unrelated destination. The expected MCP process legitimately requires the key, but the documented storage mechanism unnecessarily increases its exposure. ### Attack Path 1. A user inserts a real Octagon API key into the MCP configuration as instructed. 2. The plaintext configuration is copied into a backup, support bundle, screenshot, shared configuration repository, or another location accessible to an unauthorized party. 3. Alternatively, another local process or user reads the configuration or observes the command details. 4. The unauthorized party extracts the API key. 5. The key is reused to access Octagon services under the victim’s account until it expires or is revoked. ### Impact Assessment Exposure can permit unauthorized use of the victim’s Octagon account capabilities, consume ...[truncated 263 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is described as a commodity quote retriever, but the setup exposes broader Octagon agents for market intelligence, scraping, and deep research. This increases the effective capability surface beyond the stated purpose, which can enable overbroad data access or misuse if an agent or user invokes tools that were not necessary for commodity quotes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run an unpinned package via npx skills, which fetches whatever version is current at execution time. If the package or one of its delivery paths is compromised, users could execute attacker-controlled code during installation or setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The command npx -y octagon-mcp executes the latest published package without version pinning, creating a supply-chain risk. Because this command is also shown with a live API key in the environment, a compromised package could immediately access that credential and exfiltrate it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README tells users to place the API key directly into shell commands and configuration files but does not warn about keeping the secret out of shell history, screenshots, shared configs, or version control. This increases the likelihood of accidental credential disclosure, especially because agent and desktop config files are often copied, backed up, or committed by mistake.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The Windows example likewise runs npx -y octagon-mcp without a fixed version, so users execute whatever package version is currently available. In this context the process is launched with OCTAGON_API_KEY set, increasing the chance that any malicious package update could steal credentials or misuse the API account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section presents trading signals and position-management guidance in prescriptive terms such as 'bullish continuation,' 'follow momentum,' and 'consider profit-taking' without a clear disclaimer that the content is informational and not financial advice. In a skill designed to provide real-time commodity quotes, that framing can materially influence user financial decisions and increase the risk of harmful reliance, especially for inexperienced users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The setup instructs users to run an unpinned package via npx -y octagon-mcp, which fetches and executes whatever version is current at install time. If the upstream package is compromised, replaced, or updated with malicious code, users may execute attacker-controlled code in a trusted local environment with access to their API key and network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions tell users to embed the API key directly in shell command strings, which risks exposure through shell history, process listings, screenshots, shared config, and accidental commits. In the context of an MCP tool that makes external requests, leaked credentials could permit unauthorized API use and consumption of the user's account resources.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The Windows command also uses npx -y octagon-mcp without an exact version, creating the same supply-chain risk as the macOS/Cursor example. Because this command is intended for routine setup, users may execute remote package code without scrutiny, increasing exposure to compromised releases.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is broadly phrased and can match many ordinary user requests about commodity prices, increasing the chance the agent invokes this skill when the user did not explicitly intend to use Octagon MCP or this particular data source. Overbroad activation boundaries can cause inappropriate tool routing, unexpected external data access, and confusion about which system is answering the request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.