Back to skill

Security audit

html-easy-deploy

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it helps agents publish and manage single-file HTML pages on htmlcode.fun, with the main risks clearly tied to public deployment and version management.

Install only if you want an agent to publish single-file HTML pages to htmlcode.fun and potentially manage existing versions. Review commands before allowing overwrite, unpublish, delete, switch-current, or --output writes, because those can change public content or overwrite a local file path you provide.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- `GET /api/deploy/content?code={code}&version={version}` — read metadata and source.
- `GET /api/deploys/{code}/versions` — list version history and `likeCount`.
- `PATCH /api/deploys/{code}/versions/{version}` — overwrite or set status for an unlocked version.
- `DELETE /api/deploys/{code}/versions/{version}` — delete one unlocked version. Treat deletion as sensitive; ask first unless the user explicitly requested it.
- `PATCH /api/deploys/{code}/current` — switch the public current version when needed.

## Response handling

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents and encourages file read/write plus outbound network actions via a bundled deployment script, but it declares no explicit tool scope or permissions boundary. In an agent environment, that increases the chance the skill can invoke broader capabilities than intended, making unintended file access, modification, or remote publication harder to constrain and audit.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata says it 'instantly deploy[s] a single self-contained HTML page,' but the implementation also exposes administrative actions over existing deployments: overwriting versions, toggling active/inactive status, deleting versions, listing version history, and switching the current public version. This scope mismatch is dangerous because an agent or user may grant or invoke the skill assuming it only performs creation, while it can also modify or destroy already-deployed content, increasing the chance of unauthorized or unintended changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The advertised behavior is deployment, but the code also fetches previously deployed remote content and can write it to an arbitrary local output path. That hidden read-and-write capability broadens the trust boundary: a caller expecting only upload behavior may unknowingly use the skill to exfiltrate remote content into local files, overwrite files in the workspace, or facilitate data staging for later misuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.