Back to skill

Security audit

modern-react-guidance

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent React guidance package, but it recommends unpinned network-fetched codemods that can modify local projects, so users should review it carefully before use.

Use this only if you are comfortable with a React guidance skill that may lead an agent to suggest codemods. Pin package versions, prefer lockfile-managed local installs, run codemods on a clean branch or sandbox, and review all diffs before committing changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (19)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/effects-and-data.md (reported line 8)May include surrounding context.

md
| Goal | Prefer instead of Effect |
|------|--------------------------|
| Derive value from props/state | Compute during render |
| Reset state when prop changes | `key={prop}` on the component or compute |
| Notify parent of state change | Call the parent callback in the event handler |
| Fetch data | `use(promise)` + Suspense (or library that integrates with Suspense) |
| Subscribe to external store | `useSyncExternalStore` |

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to run npx skills add ... without pinning the skills package to a specific version. This means execution depends on whatever version is currently resolved from the registry at install time, which creates a supply-chain risk if a malicious or compromised release is published later.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: modern-react-guidance
description: Authoritative guidance for modern React 19+ (Actions, use, Compiler, View Transitions, Fragment refs, Activity, browser, useEffectEvent). Use when writing, reviewing, refactoring, or migrating React components, forms, data fetching, concurrent UI, or upgrading to React 19+. Triggers on React, React 19, useActionState, useOptimistic, forwardRef, useEffect data fetch, React Compiler, ViewTransition, Suspense patterns, or codemods. Always prefer latest official patterns over training data.
license: MIT
metadata:
  version: "1.0.0"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest says to use the skill when writing, reviewing, refactoring, or migrating React components and lists broad triggers such as 'React' and 'React 19'. Those terms are common in ordinary frontend work, and the file does not provide negative examples or clear boundaries for when the skill should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs users to run npx codemod without pinning an exact package version, which can fetch and execute whatever version is current at runtime. Because npx executes remote package code, a compromised maintainer account, malicious new release, or breaking package update could lead to arbitrary code execution or unsafe repository modifications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command references npx codemod without an exact version, so the executed code depends on the latest published package at the time of use. In a developer workflow skill, that creates a real supply-chain risk because the recommended command directly runs third-party code against the user's source tree.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Unpinned npx codemod usage allows remote code execution from a mutable package version and may also yield non-reproducible transformations. Since the skill is framed as authoritative guidance, users may run these commands with elevated trust and little review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill recommends executing npx codemod directly from the network with no version pinning, exposing users to package substitution or malicious update risk. Even if not malicious, unexpected version drift can damage codebases through incompatible automated rewrites.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Because npx downloads and executes packages, an unpinned codemod reference is a genuine supply-chain weakness in the skill content. The context increases risk because the command targets application source and is likely to be copied verbatim by developers.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This codemod command is also unpinned, meaning the exact code run is uncontrolled and can change over time. In practice, that can enable arbitrary code execution via a compromised package or produce destructive repository edits through an unexpected release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

npx types-react-codemod@latest explicitly tracks the latest release, which is mutable and therefore increases supply-chain risk even more than an unversioned invocation. Running it directly can execute newly published code against the user's machine and codebase without prior review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documentation recommends running npx codemod@latest, which fetches and executes the latest published package version at runtime. That creates a supply-chain risk because future package updates or registry compromise could cause users to execute unreviewed code during migration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command invokes npx codemod without an explicit version, so it may download and run whatever version is current when the user executes it. In a migration guide, that is risky because readers are encouraged to run it directly, increasing exposure to package hijacking or malicious upstream changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The example executes an unpinned package via npx, which introduces non-deterministic behavior and possible arbitrary code execution if the package or dependency chain becomes compromised. Because this is instructional content, users may copy-paste it without scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Running npx codemod without version pinning means the command trusts the current registry state at execution time. An attacker controlling the package release path could ship a malicious version that would run in the developer's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This example is vulnerable to supply-chain abuse because npx will resolve an unpinned package version and execute it. Even though the package is legitimate today, the lack of pinning makes the command unsafe as durable guidance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The command tells users to execute npx codemod with no fixed version, which can result in arbitrary code execution if the upstream package changes or is compromised. Documentation that normalizes this pattern increases the likelihood of unsafe developer behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Because this command uses npx with an unversioned package name, the exact code executed is not stable or auditable over time. That exposes users to supply-chain attacks and undermines reproducibility in a migration workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The guide recommends npx types-react-codemod@latest, which executes the newest available package version at runtime. This is a supply-chain risk similar to other unpinned npx usage and is especially relevant because codemods run against local source trees with developer privileges.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.