Back to skill

Security audit

MGC Blackbox — Multi‑Agent Secure Execution Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for local secret storage and script execution, but it grants broad local access to secrets and executable workflows with security claims that users should review carefully.

Install only if you trust the MGC package and intend to give it durable control over local secrets and script execution. Protect the `~/.mgc` database and token file, avoid importing or running sealed packages from untrusted sources, and understand that agents or scripts with MGC access may be able to retrieve secret values or launch stored workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs code to read a reusable bearer token from a fixed file path and use it to retrieve plaintext secrets and trigger script execution over the local API. Any malicious script, plugin, or local user/process with access to that file can impersonate the client, extract stored secrets, and execute protected workflows, making the token file a high-value target.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

python
import os, requests

# 1. Read MGC access token (fixed path, do not change)
with open(os.path.expanduser("~/.mgc/database/mgc_black_box/.mgc_token")) as f:
    MGC_TOKEN = f.read().strip()

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The documentation confirms that an access token is generated on disk at a predictable path and is required for all REST calls. Because the same API can return plaintext secrets and launch scripts, compromise of this token effectively grants broad access to the encrypted store's operational boundary despite the product's 'zero-exposure' framing.

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
- Starts HTTP server at `http://127.0.0.1:57219`
- Initializes encrypted database on first run
- Generates access token at `~/.mgc/database/mgc_black_box/.mgc_token`

This token is required for all REST API calls.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes importing sealed workflow capsules from other nodes and executing them, but it does not clearly warn that sealed packages and delegated workflows are still executable code from another party and may perform harmful actions when run. In this skill’s context, that omission is especially dangerous because the product is explicitly designed to store secrets, execute hidden scripts, and delegate cross-device workflows, which can create a strong false sense of safety around untrusted packages.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation makes a strong 'fully local/no network calls outside localhost' claim while also instructing users to exchange node public keys and sealed packages over external channels such as email, chat, or Git. Even if the software itself does not transmit externally, this is a security-relevant contradiction that can mislead users about the system's true data exposure model and trust boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
MGC_TOKEN = f.read().strip()

# --- Usage A: Retrieve a secret value ---
resp = requests.post(
    "http://127.0.0.1:57219/api/mgc/sensitive/get",
    headers={"X-MGC-Token": MGC_TOKEN},
    json={"info_type": "token", "info_owner": "openai_api_key"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
MGC_TOKEN = f.read().strip()

# --- Usage A: Retrieve a secret value ---
resp = requests.post(
    "http://127.0.0.1:57219/api/mgc/sensitive/get",
    headers={"X-MGC-Token": MGC_TOKEN},
    json={"info_type": "token", "info_owner": "openai_api_key"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
MGC_TOKEN = f.read().strip()

# --- Usage A: Retrieve a secret value ---
resp = requests.post(
    "http://127.0.0.1:57219/api/mgc/sensitive/get",
    headers={"X-MGC-Token": MGC_TOKEN},
    json={"info_type": "token", "info_owner": "openai_api_key"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
MGC_TOKEN = f.read().strip()

# --- Usage A: Retrieve a secret value ---
resp = requests.post(
    "http://127.0.0.1:57219/api/mgc/sensitive/get",
    headers={"X-MGC-Token": MGC_TOKEN},
    json={"info_type": "token", "info_owner": "openai_api_key"},

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
MGC_TOKEN = f.read().strip()

# --- Usage A: Retrieve a secret value ---
resp = requests.post(
    "http://127.0.0.1:57219/api/mgc/sensitive/get",
    headers={"X-MGC-Token": MGC_TOKEN},
    json={"info_type": "token", "info_owner": "openai_api_key"},

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
MGC_TOKEN = f.read().strip()

# --- Usage A: Retrieve a secret value ---
resp = requests.post(
    "http://127.0.0.1:57219/api/mgc/sensitive/get",
    headers={"X-MGC-Token": MGC_TOKEN},
    json={"info_type": "token", "info_owner": "openai_api_key"},

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill prominently markets safe secret storage and sealed execution, but the same interface can execute stored scripts and export workflow folders as plaintext archives. Without a clear warning in the high-level description, users may store highly sensitive workflows under the mistaken assumption that contents cannot later be materialized or used to affect system state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest describes a wide set of sensitive capabilities such as storing tokens and passwords, cross-node delegation, and execution tools, but it does not specify any narrow invocation context, explicit trigger phrases, or exclusion conditions. For a manifest file, that lack of trigger specificity can lead to overly broad or unintended invocation of a high-impact skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
65% confidence
Finding

The file makes a strong intent claim that deletion is restricted to WebUI only. However, the same document points direct API users to the server source code for complete route details, while not clearly establishing that no delete-capable REST or MCP route exists; this weakens and potentially contradicts the stated safety boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
2% confidence
Finding

No actual language or locale policy violation is present in this file. The manifest does not force a specific language or locale, so this should not be reported as a finding.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.