Back to skill

Security audit

Skill Distillation

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a documentation-style guide, but it tells users to install third-party skills through unpinned remote commands that can change what code or instructions are installed later.

Review the referenced repositories and the resolved npm package before running the installation commands. Prefer pinned package versions and immutable commit hashes, and run any installation from a least-privileged environment without unnecessary credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:52
Finding

Unpinned Third-Party Skill Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 52-58
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

bash
# Install skills distilled by SkillAlchemy
npx skills add agentsope/SkillAlchemy/skills/<skill-name>

# Install a persona skill distilled by Nuwa
npx skills add alchaincyf/nuwa-skill

# Install book-based skills distilled by Cangjie
npx skills add kangarooking/cangjie-skill

Technical Analysis

The documented commands invoke an npm-resolved CLI through npx without pinning its package version and install content from third-party GitHub repositories without immutable commit hashes, release versions, checksums, or signature verification.

Consequently, the content executed or installed when a user follows these instructions may differ from the content available when this project was audited. Compromise of the npm package, a referenced repository, a maintainer account, or a mutable upstream branch could turn the installation workflow into a supply-chain delivery channel.

The project contains documentation only, and there is no evidence that the referenced upstream projects are currently malicious. The risk arises from the unpinned and unverified trust relationship.

Attack Path

  1. An attacker compromises the npm-resolved skills package, one of the referenced GitHub repositories, or an associated maintainer account.
  2. The attacker publishes malicious installer behavior or modifies content on the mutable upstream reference.
  3. A user follows one of the documented npx skills add commands.
  4. npx resolves the unpinned CLI, and the CLI retrieves the current third-party repository content.
  5. Attacker-controlled code or skill instructions are installed or processed with the permissions available to the CLI and Agent environment.
  6. Depending on the delivered payload, the attacker may manipulate Agent behavior or access file ...[truncated 618 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm CLI to a specific audited version rather than relying on its current default resolution:
    bash
    npx skills@<audited-version> add ...
    
  2. Pin every GitHub dependency to an immutable, reviewed commit hash or cryptographically signed release where the installer supports such references.
  3. Publish expected checksums or signatures and verify downloaded artifacts before installation.
  4. Add an explicit review step requiring users to inspect all retrieved scripts, manifests, hooks, and Agent instructions before activation.
  5. Run installation in a sandbox or least-privileged environment without unnecessary credentials, sensitive environment variables, or elevated permissions.
  6. Maintain an allowlist of approved upstream versions and periodically re-audit them before updating the pinned references.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's natural-language description and instructions are presented in Chinese, which effectively imposes a language requirement on users. There is no opt-in, alternate language option, or documentation that this skill is intentionally limited to Chinese-speaking users for a specific regional purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest trigger mixes specific phrases with broader terms like "knowledge distillation" and project names such as "nuwa" and "cangjie," which can appear in unrelated conversations. The file does not provide negative examples or contextual limits, so the activation boundary is unclear and may cause unintended invocation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs users to run npx skills add ... without pinning a specific package version or documenting integrity verification. This can cause users to fetch and execute whatever package/version npx resolves at runtime, increasing supply-chain risk if the package is updated maliciously, compromised, or unexpectedly changes behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This line repeats the same unsafe installation pattern by invoking npx skills add ... without version pinning. Because npx may download and execute remote code on demand, an attacker who compromises the dependency source or publishes a harmful update could influence what users run.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The third installation example also relies on an unpinned npx command, creating the same supply-chain exposure. In a skill-distribution context, this is more concerning because the document is explicitly teaching users how to install third-party skills from external repositories, which can amplify trust-based remote code execution risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.