Back to skill

Security audit

kbo-results

Security checks for vulnerabilities and agentic risk

Overview

This KBO scoreboard skill is read-only in intent, but it tells the agent to globally install and execute an unpinned npm package, which deserves review before use.

Install only if you are comfortable with the agent modifying the global npm environment and executing the current registry version of kbo-game. Prefer using this in a sandbox or after pinning/reviewing the package version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Global npm Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23–26 and 31–40
Vulnerability Type: Insecure third-party dependency installation
Risk Level: Medium

Vulnerable Code

markdown
## Prerequisites

- Node.js 18+
- `npm install -g kbo-game`
markdown
### 0. Install the package globally when missing

`npm root -g` 아래에 `kbo-game` 이 없으면 다른 구현으로 우회하지 말고 전역 Node 패키지 설치를 먼저 시도한다.

```bash
npm install -g kbo-game
text

### Technical Analysis

The skill instructs the agent to install `kbo-game` from the npm registry globally without specifying an exact version or verifying package integrity. Consequently, the installed code can differ between executions as new releases are published.

An npm installation may execute package lifecycle scripts such as `preinstall`, `install`, and `postinstall`. Installing globally also increases the affected scope compared with an isolated, project-local dependency. The document later dynamically imports and executes the installed package, further placing trust in registry-delivered code.

This is a supply-chain exposure rather than evidence that the current `kbo-game` package is malicious. Exploitation requires compromise or hostile modification of the package, its publisher account, or the relevant package-delivery infrastructure.

### Attack Path

1. An attacker compromises the `kbo-game` package, its publisher account, or its release process.
2. The attacker publishes a malicious version under the same package name.
3. An agent follows `SKILL.md` and runs `npm install -g kbo-game` without a version or integrity constraint.
4. npm retrieves the attacker-controlled release.
5. Malicious lifecycle scripts may execute during installation.
6. The workflow subsequently imports `dist/index.js`, providing another opportunity for attacker-controlled code to execute.
7. The code runs with the permissions of the account executing npm and can affect resources accessible to that account.

### Impact Assessment

Su
...[truncated 576 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package to a reviewed exact version, for example kbo-game@0.0.2, rather than resolving the latest available release.
  2. Install the dependency locally in an isolated project directory instead of modifying the global Node.js environment.
  3. Commit and enforce a lockfile containing registry integrity metadata, and use npm ci for reproducible installation.
  4. Review the pinned package, its transitive dependencies, and any lifecycle scripts before deployment.
  5. Use --ignore-scripts when lifecycle scripts are unnecessary and compatibility testing confirms that the package still operates correctly.
  6. Run installation and execution as a dedicated, unprivileged user in a sandbox or container with minimal filesystem and network access.
  7. Restrict dependency retrieval to an approved registry or internal mirror and apply package allowlisting and provenance verification where available.
  8. Import only the locally pinned dependency and fail closed if its version or integrity does not match the approved values.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file declares locale: ko-KR, and the skill content is written entirely in Korean, which indicates a fixed language/locale behavior. The instructions do not offer user opt-in or alternative language handling, and there is no explicit justification that this skill must be restricted to Korean users only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.