Back to skill

Security audit

turing-shikuan-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent product-recognition MCP integration, but setup handles API secrets and installs a global npm helper in ways users should review.

Before installing, confirm you trust the Turing MCP endpoint and use scoped or revocable API credentials. Run setup without sudo where possible, review the global mcporter install, and rotate the API key/secret if your environment logs process command lines.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
setup.sh:12
Finding

Unpinned Global npm Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: setup.sh, lines 12-16
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Vulnerable Code:

bash
if ! command -v mcporter >/dev/null 2>&1; then
  echo "mcporter not found. Installing mcporter..."
  npm install -g mcporter
  echo "mcporter installed."
fi

Technical Analysis

The setup script installs the latest version of the mcporter npm package without pinning a reviewed version or verifying package integrity. npm packages can execute lifecycle scripts during installation. Consequently, the effective code executed by this setup process may change after the skill has been audited.

The global installation option, -g, also modifies the invoking user's global npm environment rather than isolating the dependency within the project. If the package, one of its transitive dependencies, or the registry delivery path is compromised, arbitrary package lifecycle code could execute with the permissions of the user running setup.sh.

Attack Path

  1. An attacker compromises the mcporter npm package, one of its transitive dependencies, or the associated package publication account.
  2. The attacker publishes a malicious version containing an installation lifecycle script or modified executable code.
  3. A user without an existing mcporter command runs bash setup.sh.
  4. npm install -g mcporter retrieves the current unpinned release and executes any applicable lifecycle scripts.
  5. The malicious code runs with the operating-system privileges of the invoking user and modifies the global npm environment.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user running the setup script. It could access files and credentials available to that user, alter globally installed npm tools, or modify user-level configuration. If the script is run from an elevated ...[truncated 206 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin mcporter to a specifically reviewed version rather than installing the latest release implicitly.
  • Verify package provenance and integrity using an approved lockfile, registry policy, or cryptographic integrity metadata.
  • Prefer a project-local dependency over npm install -g to reduce the scope of filesystem and environment modifications.
  • Disable npm lifecycle scripts where compatible with the package and deployment process.
  • Require explicit user approval before installing software, and document the exact package version and source.
  • Execute installation with the least-privileged account required and avoid running the setup script as root or through sudo.

T09 · Insecure Skill Coding Practices

Warning
Location
setup.sh:37
Finding

API Credentials Exposed Through Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: setup.sh, lines 37-40
Vulnerability Type: Sensitive credentials passed in process arguments
Risk Level: Medium

Vulnerable Code:

bash
echo "Registering ${MCP_NAME} with mcporter..."
mcporter config add "${MCP_NAME}" "${MCP_URL}" \
  --header "x-api-key=${API_KEY}" \
  --header "x-api-secret=${API_SECRET}" \
  --scope project

Technical Analysis

The script expands the API key and API secret directly into arguments passed to the mcporter process. Although shell quoting prevents word splitting, it does not conceal the expanded values from operating-system process metadata.

While the command is running, the credentials may be observable through process inspection facilities, endpoint monitoring, audit telemetry, crash diagnostics, or command-execution logging. The precise visibility of another user's process arguments depends on the operating system and local hardening configuration, but placing secrets in the argument vector unnecessarily broadens their exposure.

The command also writes a project-scoped MCP configuration. The reviewed script does not verify the resulting file's location, permissions, or whether mcporter stores the header values in plaintext.

Attack Path

  1. A user exports valid Turing API credentials and runs bash setup.sh.
  2. The shell expands API_KEY and API_SECRET into the mcporter config add argument vector.
  3. During execution, a local process, authorized monitoring agent, audit facility, or diagnostic collector captures the command-line arguments.
  4. The observer extracts the values supplied in the x-api-key and x-api-secret headers.
  5. The exposed credentials are reused to make unauthorized requests to the configured external MCP service, subject to the permissions and limits assigned to those credentials.

Impact Assessment

Exploitation could disclose the API key and API secret to a local observer ...[truncated 347 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not place raw secrets in command-line arguments.
  • Use a supported secret-input mechanism such as standard input, an inherited environment-variable reference, an operating-system credential store, or an interactive hidden prompt.
  • If mcporter cannot accept secrets securely, generate the configuration through a protected file descriptor or permission-restricted temporary file and remove it immediately after use.
  • Ensure any persistent MCP configuration containing credentials is created with owner-only permissions, such as mode 0600.
  • Confirm that verification and diagnostic commands redact header values before printing configuration details.
  • Rotate the API credentials if process monitoring, audit logs, or diagnostic collection may already have recorded them.
  • Apply service-side least privilege, expiration, usage limits, and credential rotation to reduce the impact of disclosure.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown explicitly requires output to be '适合中文用户阅读', which imposes a specific language/locale preference. The file does not provide an option to match the user's language or ask for consent, so this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script registers an external MCP endpoint and passes API credentials as headers, which results in those secrets being transmitted off-host during setup. While this appears necessary for the advertised integration and not overtly malicious, the script gives no explicit warning, consent prompt, or trust guidance before sending credentials to a non-local service, increasing the risk of unintended secret disclosure or misconfiguration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.