mcp-security

Fail

Audited by Snyk on May 4, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This content contains explicit, actionable malicious payloads and techniques—including instructions to read and exfiltrate private keys and environment files to attacker-controlled endpoints, steal OAuth/API tokens across servers, hijack or shadow trusted tools to alter behavior, and use obfuscation (base64, ANSI escape sequences, zero‑width/Unicode tags) and dynamic description tampering for stealth—indicating deliberate backdoor/data‑exfiltration and supply‑chain abuse behavior.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to enumerate connected MCP Servers and "获取所有工具的完整 description" (Phase 0/Phase 1), i.e. fetch and parse untrusted/third‑party MCP server tool descriptions which the agent is expected to read/interpret and which can materially alter tool-calling decisions.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 4, 2026, 08:15 AM
Issues
2
Security Audit — snyk — mcp-security