Back to skill

Security audit

easy-html-deploy

Security checks for vulnerabilities and agentic risk

Overview

This skill publishes and manages single-file HTML pages on htmlcode.fun, with its upload and version-management behavior disclosed and scoped to that service.

Use this only for HTML you are comfortable sending to and publishing on htmlcode.fun. Confirm the code and version before overwrite, status, current-version, or delete operations, and avoid deploying files containing secrets or private data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description frames the skill as simple HTML deployment, but the body includes additional content retrieval and state-changing administrative actions such as version overwrite, delete, and switching the current public version. This mismatch is dangerous because downstream agents or users may authorize the skill for low-risk publishing while it actually enables broader modification and disclosure operations against existing deployments.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The skill exposes a deletion endpoint for deployed versions and also documents other mutable version-management operations. Even with the note to ask first, this creates a real risk of parameter abuse or accidental destructive action if an agent is prompted to act on attacker-supplied codes/versions or if confirmation logic is bypassed, leading to deletion or alteration of public content.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- `GET /api/deploy/content?code={code}&version={version}` — read metadata and source.
- `GET /api/deploys/{code}/versions` — list version history and `likeCount`.
- `PATCH /api/deploys/{code}/versions/{version}` — overwrite or set status for an unlocked version.
- `DELETE /api/deploys/{code}/versions/{version}` — delete one unlocked version. Treat deletion as sensitive; ask first unless the user explicitly requested it.
- `PATCH /api/deploys/{code}/current` — switch the public current version when needed.

## Response handling

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents file read/write and network-capable behavior but declares no explicit tool scope or permission boundary. That omission can let an agent invoke broader capabilities than a user would reasonably infer from the metadata, increasing the chance of unintended local file access or outbound publication actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill to 'Deploy a single self-contained HTML page to htmlcode.fun for instant sharing,' which implies creating and publishing a page. The code also supports overwriting versions, toggling active/inactive status, deleting versions, switching the current public version, and fetching content, which is materially broader than straightforward deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code POSTs the full HTML file content and metadata to htmlcode.fun, which transmits user-provided data over the network. Although the CLI help says it will deploy pages, there is no runtime disclosure, confirmation, or inline comment near the transmission point warning that local file contents are being sent to an external service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest focuses on taking a local self-contained HTML page and deploying it for sharing. The get command performs the reverse operation by downloading previously deployed remote content and optionally writing it to a local file, which is outside the stated deployment-only scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

When --output is used, this function writes fetched remote content directly to a local path. The operation is user-directed, but there is no nearby warning or disclosure that local files may be created or overwritten as part of the fetch operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.