Back to skill

Security audit

Remix V2 Perf Ssr

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Remix performance skill with some examples that require care, but I found no hidden execution, persistence, credential collection, or purpose-mismatched behavior.

Install only if you want Remix v2 SSR and performance guidance. Treat the window.ENV examples carefully: expose public values only and prefer the serializer pattern rather than copying the initial JSON.stringify snippet unchanged.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/prefetch.md (reported line 94)May include surrounding context.

md
**Gotcha**: the `page` prop must be an **absolute path** (starts with `/`). Relative paths silently fail — no warning, no prefetch.

Unvalidated Output Injection

High
Category
Output Handling
Confidence
98% confidence
Finding

The example injects window.ENV into an inline <script> using JSON.stringify, which does not escape </script> or U+2028/U+2029. If any supposedly public env value contains attacker-controlled content, it can break out of the script context and lead to XSS; the surrounding skill context explicitly warns that this pattern is unsafe, which confirms the risk rather than mitigating it.

Content

Scanner excerpt · references/server-client-split.md (reported line 139)May include surrounding context.

md
<Outlet />
        <ScrollRestoration />
        <script
          dangerouslySetInnerHTML={{
            __html: `window.ENV = ${JSON.stringify(data.ENV)}`,
          }}
        />

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · references/server-client-split.md (reported line 171)May include surrounding context.

md
import serialize from "serialize-javascript";

<script
  dangerouslySetInnerHTML={{
    __html: `window.ENV = ${serialize(data.ENV, { isJSON: true })}`,
  }}
/>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description includes a long list of broad trigger tokens such as generic framework APIs and common identifiers (headers export, window.ENV, window, useId). This can cause the skill to activate in many loosely related contexts, increasing the chance that an agent applies Remix-specific caching or server/client guidance where it is not appropriate, which can mislead downstream code generation or review decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prose at L239 states that a matching conditional request should return 204 to skip the body, but the sample implementation at L248-L249 returns 304, which is the correct HTTP status for If-None-Match revalidation. This is an active contradiction between documentation intent and code behavior, even though the code is correct.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The guidance recommends fixing locale-sensitive formatting by explicitly passing "en-US" in Intl.DateTimeFormat, which can be read as prescribing a specific language/locale choice. The file does not mention offering user locale selection or limiting this advice to a justified region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example sets <html lang="en"> explicitly, which is a natural-language locale choice. Under the policy for this audit, forcing a specific language/locale without user opt-in or documented justification is a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.