Back to skill

Security audit

Harness Dev Standards

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real code-quality skill, but it can automatically change projects and install or run unpinned npm tools, so it needs careful review before use.

Review this skill before installing. Use it only on projects where you are comfortable with automated code and dependency changes, inspect diffs before accepting fixes, avoid running the bundled scripts in sensitive or production workspaces, and prefer locally pinned devDependencies over the script's global depcheck install or unpinned npx behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
scripts/depcheck.sh:20
Finding

Unpinned Packages May Be Downloaded and Executed During Quality Scans

Content
View full analysis
/dev/null; then echo "Installing depcheck..." npm install -g depcheck fi ``` Related commands: ```bash if npx tsc --noEmit 2>&1; then ``` ```bash if npx eslint . --ext .ts,.tsx,.js,.jsx --quiet 2>&1; then ``` ### Technical Analysis The dependency scanner installs the latest registry version of `depcheck` globally without a version constraint or lockfile verification. The aggregate scanner also invokes `npx` without disabling package installation. When an appropriate local executable is unavailable, `npx` may retrieve and execute a package from the configured npm registry. In particular, the command name `tsc` does not by itself guarantee that the executable originated from the intended lockfile-managed `typescript` package. This creates a supply-chain trust boundary in a tool advertised as a local quality scanner. Its behavior can vary over time according to mutable registry content, registry configuration, and the packages already installed on the host. ### Attack Path 1. A user runs `depcheck.sh` or `quality-scan.sh` as documented. 2. The expected executable is missing from the local environment. 3. The script contacts the configured npm registry and downloads an unpinned package. 4. Package lifecycle scripts or the downloaded executable run with the user's permissions. 5. If the package, registry, or package-resolution path is compromised, attacker-controlled code can access files and resources available to that user. ### Impact Assessment Successful exploitation permits arbitrary code execution with the privileges of the user running the scan. The accessible scope can include ...[truncated 427 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/quality-scan.sh:51
Finding

Malformed Shell Quoting Prevents Reliable Dependency Audit Execution

Content
View full analysis
&1; then echo "✅ Dependency check passed" PASSED=$((PASSED + 1)) else echo "❌ Dependency check found issues" FAILED=$((FAILED + 1)) fi echo "" ``` ### Technical Analysis The opening quotation mark before `$SCRIPT_DIR` is not closed after the script path. Consequently, the intended executable path and redirection are not represented as: ```bash "$SCRIPT_DIR/depcheck.sh" 2>&1 ``` Instead, subsequent source text may be consumed as part of the quoted shell token until another quotation mark is encountered. This corrupts shell parsing and prevents reliable execution of the dependency-checking script. Because this command represents the aggregate scanner's dependency and vulnerability gate, the defect undermines a security-relevant control rather than merely affecting cosmetic output. ### Attack Path 1. A user relies on `quality-scan.sh` as the advertised aggregate delivery gate. 2. Execution reaches the malformed dependency-check command. 3. Shell parsing does not invoke `depcheck.sh` in the intended manner. 4. The dependency and vulnerability checks either fail, terminate the aggregate scanner, or produce unreliable status handling. 5. The user may proceed without a valid dependency audit, particularly if the failure is mistaken for a tooling problem and bypassed. This is primarily a control-failure path; the malformed line does not independently grant an attacker code execution. ### Impact Assessment The direct impact is loss of integrity and availability of the quality gate. Undeclared dependencies, unused dependencies, or known vulnerabilities may remain unreported. No additional ...[truncated 130 chars]
Remediation
View remediation
&1; then echo "✅ Dependency check passed" PASSED=$((PASSED + 1)) else echo "❌ Dependency check found issues" FAILED=$((FAILED + 1)) fi ``` Add the following safeguards: 1. Run `bash -n scripts/quality-scan.sh` in CI. 2. Add ShellCheck with failures enforced for malformed quoting and command construction. 3. Add an integration test that confirms `depcheck.sh` is actually invoked. 4. Verify that each advertised gate contributes an explicit pass, failure, or operational-error result. 5. Treat failure to execute a security check as a failed scan, not as a skipped or successful check. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/depcheck.sh:30
Finding

Incorrect Depcheck JSON Parsing Terminates the Audit Before Security Checks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/depcheck.sh:83
Finding

NPM Audit Operational Failures Are Reported as Zero Vulnerabilities

Content
View full analysis
/dev/null || true) HIGH_VULNS=$(echo "$AUDIT_OUTPUT" | node -e " try { const data = JSON.parse(require('fs').readFileSync(0, 'utf-8')); console.log(data.metadata.vulnerabilities.high || 0); } catch(e) { console.log(0); }") CRITICAL_VULNS=$(echo "$AUDIT_OUTPUT" | node -e " try { const data = JSON.parse(require('fs').readFileSync(0, 'utf-8')); console.log(data.metadata.vulnerabilities.critical || 0); } catch(e) { console.log(0); }") ``` ### Technical Analysis The command suppresses standard error and forces every `npm audit` exit status to success using `|| true`. Both JSON parsers then convert malformed, empty, incomplete, or schema-incompatible output into a count of zero. As a result, the script cannot distinguish among: - A successful audit with no vulnerabilities - Registry or network failure - Missing or invalid lockfile - Authentication or registry-configuration failure - Unsupported npm output format - Truncated or malformed JSON The later logic interprets zero values as a clean result and prints that no high-risk vulnerabilities were found. This is a fail-open security control. ### Attack Path 1. A project contains high- or critical-severity vulnerable dependencies. 2. The audit request is made to fail, such as through unavailable networking, invalid registry configuration, authentication failure, or malformed audit output. 3. `2>/dev/null` hides diagnostic information. 4. `|| true` discards the operational failure status. 5. JSON parsing fails or required fields are unavailable. 6. The catch blocks emit zero for high and critical findings. 7. The script reports a clean vulnerability result and may allow delivery to proceed. An attacker who can influence project npm configuration or the audit e ...[truncated 613 chars]
Remediation
View remediation
&1) AUDIT_STATUS=$? set -e if ! printf '%s' "$AUDIT_OUTPUT" | node -e ' const fs = require("fs"); const data = JSON.parse(fs.readFileSync(0, "utf8")); if (!data.metadata || !data.metadata.vulnerabilities) { throw new Error("Invalid npm audit JSON schema"); } '; then echo "❌ npm audit failed or returned invalid JSON" >&2 printf '%s\n' "$AUDIT_OUTPUT" >&2 exit 2 fi ``` The complete hardening plan should: 1. Never translate parsing or network errors into zero findings. 2. Use separate states for clean, vulnerabilities detected, and audit operational failure. 3. Fail the quality gate when the audit cannot be completed. 4. Retain sanitized diagnostic output so failures can be investigated. 5. Validate the expected npm audit JSON schema before reading severity counts. 6. Test registry failure, missing lockfile, malformed JSON, clean results, and known vulnerable fixtures. 7. Run audits in a controlled CI environment with a trusted registry and predictable npm version. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (28)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs automatic remediation of dependencies, imports, syntax, startup failures, and types without requiring user approval or warning about side effects. In a development environment, such autonomous code and dependency changes can introduce supply-chain risk, break builds, alter behavior, or silently modify security-relevant logic.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · marketing/01-vs-superpowers.md (reported line 47)May include surrounding context.

md
- 代码风格好不好
- 依赖干不干净
- README 写没写清楚
- .env 配置有没有注释

**它只保证「过程正确」,不保证「结果合格」。**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/remediation.md (reported line 403)May include surrounding context.

md
- 代码风格好不好
- 依赖干不干净
- README 写没写清楚
- .env 配置有没有注释

**它只保证「过程正确」,不保证「结果合格」。**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/remediation.md (reported line 405)May include surrounding context.

md
- 代码风格好不好
- 依赖干不干净
- README 写没写清楚
- .env 配置有没有注释

**它只保证「过程正确」,不保证「结果合格」。**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/checklist.md (reported line 52)May include surrounding context.

md
- [ ] .env.example 包含所有配置项
- [ ] 每个配置项有说明注释
- [ ] .env.local 已加入 .gitignore
- [ ] 敏感信息未提交到 git
- [ ] .gitignore 配置正确

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/standards.md (reported line 60)May include surrounding context.

md
- [ ] .env.example 包含所有配置项
- [ ] 每个配置项有说明注释
- [ ] .env.local 已加入 .gitignore
- [ ] 敏感信息未提交到 git
- [ ] .gitignore 配置正确

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/standards.md (reported line 297)May include surrounding context.

md
- [ ] .env.example 包含所有配置项
- [ ] 每个配置项有说明注释
- [ ] .env.local 已加入 .gitignore
- [ ] 敏感信息未提交到 git
- [ ] .gitignore 配置正确

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description is very broad and can trigger in many ordinary development contexts, increasing the chance that the skill is invoked when the user did not specifically request this workflow. In a skill that prescribes process gates and automated fixes, overbroad activation can cause unintended influence over developer actions and decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Nearly all user-facing instructional content is written in Chinese, and the skill does not state that language is optional or user-selectable. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is explicit and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents the skill description and usage instructions exclusively in Chinese, including the title, feature descriptions, and installation steps. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill-facing markdown is written exclusively in Chinese with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The remediation guidance recommends killing a process with kill -9 <PID> without an explicit warning to verify the process owner, role, or side effects. In an automated or semi-automated repair context, this can terminate unrelated services, disrupt production workloads, or cause data loss if users follow it mechanically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该 markdown 文件从标题开始即以中文规定规范内容,全文未说明是否允许其他语言版本,也未提供用户语言/locale 选择。根据规则,强制特定语言而无用户选择可构成自然语言层面的语言/地区政策违规。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script automatically runs npm install -g depcheck if depcheck is missing, which modifies the host environment without explicit user consent. Installing a global package also executes package lifecycle scripts and depends on the integrity of the npm registry and the resolved package version, creating unnecessary supply-chain and privilege risk for what should be a read-only check.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script contains natural-language comments and runtime output in Chinese, and the user-facing console messages throughout the script are likewise fixed to that language. Because the file does not provide any opt-in, fallback, or justification for a Chinese-only locale, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is written entirely in Chinese and presents the content as the default user-facing material, with no indication that other languages are supported or that the locale is intentionally limited for a specific regional audience. Under the policy, a fixed language/locale without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

该 markdown 文件全部以中文编写,未说明是否允许用户选择其他语言,也未给出该语言限制的业务或地域性理由。根据语言/locale 政策,这属于未经用户选择的语言强制约束。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.