Back to skill

Security audit

agent-exporter Archive Governance Workbench

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and not malicious, but it asks the host to run an external, unpinned MCP bridge from a local checkout that is not included in the reviewed artifact.

Review the exact agent-exporter checkout before installing, prefer an official immutable release or commit, and only wire the MCP config to a bridge path you trust. Run it with the narrowest workspace and host permissions available because the reviewed skill documents the bridge but does not include or verify the code that will execute.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/INSTALL.md:5
Finding

Unpinned External MCP Implementation Executed by the Host

Content
View full analysis

Vulnerability Details

File Location: references/INSTALL.md:5-15, references/OPENCLAW_MCP_CONFIG.json:4-6, and references/OPENHANDS_MCP_CONFIG.json:4-6
Vulnerability Type: Unverified external executable dependency
Risk Level: Medium

Complete Code Snippets

references/INSTALL.md:5-15:

markdown
1. a local checkout of `agent-exporter`
2. `python3`
3. either:
   - `target/release/agent-exporter`
   - `target/debug/agent-exporter`
   - or a working `cargo` toolchain

The bridge script is:

```text
/absolute/path/to/agent-exporter/scripts/agent_exporter_mcp.py
text

`references/OPENCLAW_MCP_CONFIG.json:4-6`:

```json
"command": "python3",
"args": [
  "/absolute/path/to/agent-exporter/scripts/agent_exporter_mcp.py"
]

references/OPENHANDS_MCP_CONFIG.json:4-6:

json
"command": "python3",
"args": [
  "/absolute/path/to/agent-exporter/scripts/agent_exporter_mcp.py"
]

Technical Analysis

The package directs an AI host to execute scripts/agent_exporter_mcp.py from a separately obtained repository checkout. The installation instructions do not identify a canonical clone URL, require an immutable commit or release, or prescribe checksum or signature verification.

The referenced Python implementation is not included in the audited artifact. Therefore, this package cannot establish what code will receive MCP requests, which subprocesses it may launch, or whether its access to local workspaces and transcript artifacts is restricted as documented.

This creates a supply-chain trust boundary: the security of the configured MCP server depends entirely on the provenance and integrity of an external checkout. An attacker who controls or modifies that checkout can replace the expected bridge with arbitrary Python code while retaining the legitimate-looking path and MCP server name.

Attack Path

  1. An attacker distributes a modified agent-exporter checkout, compromises its source location, or alters an existing local checko ...[truncated 1286 chars]
Remediation
View remediation

Remediation Suggestions

  1. Identify the authoritative source: Provide the exact official repository URL rather than referring only to “a local checkout.”
  2. Pin an immutable revision: Require a specific audited commit hash or immutable signed release instead of a mutable branch or unspecified checkout.
  3. Verify integrity: Publish and verify a SHA-256 digest or cryptographic signature for agent_exporter_mcp.py and any binary it invokes.
  4. Bundle reviewed code where practical: Include the MCP bridge implementation in the reviewed package, or distribute it as a separately versioned and signed artifact.
  5. Validate before registration: Document commands or host-side checks that reject the bridge when its digest does not match the expected value.
  6. Apply least privilege: Run the MCP server in a sandbox with access limited to explicitly selected workspace directories. Deny unrelated filesystem, credential, subprocess, and network access unless required.
  7. Protect the checkout: Ensure the checkout and bridge script are owned by a trusted account and are not writable by untrusted users.
  8. Review transitive execution: Pin and verify the agent-exporter binary or Cargo dependencies that the bridge may invoke, not only the Python entry point.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.