T03 · Remote Payload Retrieval and Execution
- Location
references/mcp-setup.md:18- Finding
Unverified Remote Homebrew Installer Is Executed Directly by Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent commodity quote helper, but its setup asks users to run mutable remote packages and store an API key in persistent agent configs, so it should be reviewed carefully before installation.
Install only if you trust OctagonAI and the npm/package sources involved. Prefer pinning octagon-mcp and installer versions, review package provenance before running them, avoid curl-to-bash setup where possible, store the Octagon API key in a protected secret mechanism rather than shared config files, and treat the commodity analysis as informational rather than trading advice.
references/mcp-setup.md:18Unverified Remote Homebrew Installer Is Executed Directly by Bash
references/mcp-setup.md:55Unpinned npm Packages Are Automatically Downloaded and Executed
references/mcp-setup.md:55Octagon API Key Is Stored in Plaintext MCP Configuration
The skill is described as a commodity quote retriever, but the setup exposes broader Octagon agents for market intelligence, scraping, and deep research. This increases the effective capability surface beyond the stated purpose, which can enable overbroad data access or misuse if an agent or user invokes tools that were not necessary for commodity quotes.
The README instructs users to run an unpinned package via npx skills, which fetches whatever version is current at execution time. If the package or one of its delivery paths is compromised, users could execute attacker-controlled code during installation or setup.
The command npx -y octagon-mcp executes the latest published package without version pinning, creating a supply-chain risk. Because this command is also shown with a live API key in the environment, a compromised package could immediately access that credential and exfiltrate it.
The README tells users to place the API key directly into shell commands and configuration files but does not warn about keeping the secret out of shell history, screenshots, shared configs, or version control. This increases the likelihood of accidental credential disclosure, especially because agent and desktop config files are often copied, backed up, or committed by mistake.
The Windows example likewise runs npx -y octagon-mcp without a fixed version, so users execute whatever package version is currently available. In this context the process is launched with OCTAGON_API_KEY set, increasing the chance that any malicious package update could steal credentials or misuse the API account.
This section presents trading signals and position-management guidance in prescriptive terms such as 'bullish continuation,' 'follow momentum,' and 'consider profit-taking' without a clear disclaimer that the content is informational and not financial advice. In a skill designed to provide real-time commodity quotes, that framing can materially influence user financial decisions and increase the risk of harmful reliance, especially for inexperienced users.
The setup instructs users to run an unpinned package via npx -y octagon-mcp, which fetches and executes whatever version is current at install time. If the upstream package is compromised, replaced, or updated with malicious code, users may execute attacker-controlled code in a trusted local environment with access to their API key and network.
The instructions tell users to embed the API key directly in shell command strings, which risks exposure through shell history, process listings, screenshots, shared config, and accidental commits. In the context of an MCP tool that makes external requests, leaked credentials could permit unauthorized API use and consumption of the user's account resources.
The Windows command also uses npx -y octagon-mcp without an exact version, creating the same supply-chain risk as the macOS/Cursor example. Because this command is intended for routine setup, users may execute remote package code without scrutiny, increasing exposure to compromised releases.
The skill description is broadly phrased and can match many ordinary user requests about commodity prices, increasing the chance the agent invokes this skill when the user did not explicitly intend to use Octagon MCP or this particular data source. Overbroad activation boundaries can cause inappropriate tool routing, unexpected external data access, and confusion about which system is answering the request.
No suspicious patterns detected.