Back to skill

Security audit

Alon Search Skill Plus

Security checks for vulnerabilities and agentic risk

Overview

The skill itself is a purpose-aligned search guide, but its install instructions use unpinned remote code that should be reviewed before use.

Review the installer path before installing. Prefer a pinned package version and pinned repository commit, avoid running the `npx` command with elevated privileges, and remember that runtime searches will send queries to the listed external sources and may surface lower-trust results that need manual review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:8
Finding

Unpinned Third-Party Installer Execution in English Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 7-9
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code:

bash
npx skills add alondotsh/alon-skills --skill alon-search-skill-plus

Technical Analysis

The documented installation command invokes the third-party skills npm package through npx without specifying an exact package version or verifying its integrity. If the package is unavailable locally, npx can retrieve its current release from the configured npm registry and execute its command-line entry point.

Consequently, the code executed during installation is mutable and may differ from the code reviewed during this audit. The command also directs the installer to retrieve skill content from the external alondotsh/alon-skills repository without pinning that content to an audited commit. This creates a supply-chain trust dependency on both the npm package and the referenced repository.

Attack Path

  1. An attacker compromises the npm account, package publishing process, registry resolution path, or referenced repository.
  2. The attacker publishes a malicious release or modifies the remotely retrieved skill content.
  3. A user follows the documented Quick Install command.
  4. npx resolves and executes the mutable package release, which retrieves the current external skill content.
  5. Malicious installer behavior executes with the permissions of the user running the command.

Impact Assessment

A compromised installer could execute commands with the invoking user's privileges. Depending on those privileges and the malicious payload, this could expose accessible files, environment variables, tokens, source repositories, and application data, or modify user-owned files and development configuration. System-wide impact would require the command to be run with elevated privileges or a separate privilege-escalation flaw.

Remediation
View remediation

Remediation Suggestions

  • Pin the skills npm package to an exact, reviewed version rather than allowing npx to resolve the latest release.
  • Pin the installed skill source to an audited commit hash or immutable release tag where the installer supports it.
  • Document the expected npm publisher, source repository, and package provenance so users can verify them before execution.
  • Provide checksums, signatures, or registry integrity information for reviewed releases.
  • Offer a manual installation procedure that downloads a pinned revision for inspection before any installer code is executed.
  • Advise users not to run the installation command with administrative privileges.

T08 · Insecure Dependencies

Warning
Location
README.zh.md:8
Finding

Unpinned Third-Party Installer Execution in Chinese Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: README.zh.md, lines 7-9
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code:

bash
npx skills add alondotsh/alon-skills --skill alon-search-skill-plus

Technical Analysis

The documented installation command invokes the third-party skills npm package through npx without specifying an exact package version or verifying its integrity. If the package is unavailable locally, npx can retrieve its current release from the configured npm registry and execute its command-line entry point.

The effective installer code can therefore change after this project has been reviewed. In addition, the selected skill is retrieved from the external alondotsh/alon-skills repository without an immutable commit reference. Trust is consequently delegated to mutable npm and repository content.

Attack Path

  1. An attacker compromises the relevant npm package, publishing account, dependency delivery path, or external skill repository.
  2. The attacker places malicious behavior in a new package release or in the remotely retrieved skill content.
  3. A user copies and runs the documented installation command.
  4. npx retrieves and executes the attacker-controlled package version.
  5. The malicious code operates under the invoking user's account.

Impact Assessment

Successful exploitation could provide the malicious installer with the same access as the user running it, including access to readable files, environment variables, development credentials, repositories, and user-level configuration. It could also alter or delete user-owned data. Administrative or system-wide access is not inherent and would depend on the user running the installer with elevated privileges or on an additional vulnerability.

Remediation
View remediation

Remediation Suggestions

  • Replace the unversioned npx skills invocation with an exact, audited package version.
  • Reference an immutable commit or verified release of alondotsh/alon-skills.
  • Publish package provenance and integrity-verification instructions.
  • Provide a manual, review-before-execution installation alternative.
  • Keep installation instructions consistent across all language variants.
  • Explicitly warn users not to execute the installer with elevated privileges.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
| GitHub code search | github.com/search | Finds repos containing `SKILL.md`, `plugin.json`, or skill-like workflows | `Standalone Skill Repo` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
| GitHub code search | github.com/search | Finds repos containing `SKILL.md`, `plugin.json`, or skill-like workflows | `Standalone Skill Repo` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
| GitHub code search | github.com/search | Finds repos containing `SKILL.md`, `plugin.json`, or skill-like workflows | `Standalone Skill Repo` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
| GitHub code search | github.com/search | Finds repos containing `SKILL.md`, `plugin.json`, or skill-like workflows | `Standalone Skill Repo` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
| GitHub code search | github.com/search | Finds repos containing `SKILL.md`, `plugin.json`, or skill-like workflows | `Standalone Skill Repo` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
| GitHub code search | github.com/search | Finds repos containing `SKILL.md`, `plugin.json`, or skill-like workflows | `Standalone Skill Repo` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
| GitHub code search | github.com/search | Finds repos containing `SKILL.md`, `plugin.json`, or skill-like workflows | `Standalone Skill Repo` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

md
| GitHub code search | github.com/search | Finds repos containing `SKILL.md`, `plugin.json`, or skill-like workflows | `Standalone Skill Repo` |

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run npx skills add alondotsh/alon-skills --skill alon-search-skill-plus without pinning a specific package version. npx resolves and executes the current package release, so if the upstream package is later compromised, typosquatted, or updated with malicious code, users following the install instructions could execute unreviewed code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to run npx skills add ... without pinning a specific package version, which can cause execution of whatever package version is current at install time. If the upstream package or a dependency is compromised, users may unknowingly execute malicious code during installation.

Content

No source excerpt is available for this finding.

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: alon-search-skill-plus
description: Search agent skills across trusted directories, ClawHub, and GitHub adaptation candidates with explicit ranking and safety filters.
version: 0.1.4
model: sonnet
---

# Search Skill Plus

Static analysis

No suspicious patterns detected.