Back to skill

Security audit

Leave Task

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it performs authenticated task changes through an unpinned npm CLI that can change after review.

Review before installing. The workflow is user-confirmed and narrowly focused on leaving OpenAnt tasks, but install it only if you trust the OpenAnt CLI package release process or can replace @latest with a pinned, reviewed version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:6
Finding

Mutable npm Package Executed Through the @latest Tag

Content
View full analysis
--json npx @openant-ai/cli@latest tasks unassign --json ``` ### Technical Analysis The Skill invokes an npm package through `npx` while selecting its version with the mutable `@latest` distribution tag. Consequently, the code executed during future Skill invocations is not necessarily the code that existed when the Skill was reviewed. Depending on the local npm cache and `npx` configuration, the command may retrieve and execute a package release directly from the npm registry. A malicious or compromised future release could therefore execute arbitrary package lifecycle or CLI code with the privileges and environment of the Agent process. This creates a supply-chain trust boundary outside the audited project. The repository does not pin an exact package version, provide a lockfile or integrity hash, or include the dependency implementation for review. ### Attack Path 1. An attacker compromises the npm package, its publisher account, or the associated release process. 2. The attacker publishes a malicious package version and causes the `latest` tag to reference it. 3. A user asks the Agent to perform an operation covered by this Skill. 4. The Agent runs a documented command such as `npx @openant-ai/cli@latest status --json`. 5. `npx` retrieves and executes the attacker-controlled package version. 6. The package executes with the local privileg ...[truncated 1066 chars]
Remediation
View remediation
status --json ``` 2. Prefer installing the audited dependency during a controlled build or deployment phase rather than downloading executable code whenever the Skill runs. 3. Commit a lockfile that records the complete transitive dependency graph and integrity metadata. 4. Enforce registry and integrity verification in CI/CD, and reject unexpected package or lockfile changes. 5. Review package lifecycle scripts and transitive dependencies before approving version upgrades. 6. Run the CLI with least privilege in a sandboxed environment, exposing only the files, network destinations, environment variables, and narrowly scoped OpenAnt credentials required for the requested operation. 7. Update the `allowed-tools` entries and every command in `SKILL.md` consistently so no invocation can continue to select the mutable `latest` release. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The final manifest occurrence also relies on @latest, reinforcing a systematic lack of version pinning rather than an isolated mistake. The skill context makes this more dangerous because the CLI operates on authenticated OpenAnt task state, so compromise could affect both local execution integrity and remote account actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The allowed-tools list includes npx @openant-ai/cli@latest tasks get *, which still requires downloading and executing remote code at runtime. Even read-oriented commands are dangerous here because a compromised package can run arbitrary pre/post install or command code and harvest environment data or auth tokens.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The documentation instructs use of npx @openant-ai/cli@latest as the standard execution path. This normalizes unsafe runtime package resolution and increases the chance that operators or downstream systems will repeatedly execute unreviewed code from the registry.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The authentication check command uses npx @openant-ai/cli@latest status --json, meaning the code that handles authenticated state is fetched live each time. Since this command likely touches session details, a compromised package could capture authentication material or misreport state to influence subsequent actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The task inspection step uses npx @openant-ai/cli@latest tasks get <taskId> --json, again exposing the workflow to arbitrary upstream code changes. Because this command is part of a decision gate before unassigning, malicious behavior could falsify task metadata or silently perform unauthorized API actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The unassign step directly performs a state-changing action through npx @openant-ai/cli@latest tasks unassign <taskId> --json. This is especially dangerous because a malicious update could not only run arbitrary code but also alter, expand, or conceal destructive task-management operations under the guise of a legitimate unassign.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The example command npx @openant-ai/cli@latest tasks get ... --json propagates the same unsafe pattern to users and maintainers. Although this line is illustrative, examples materially influence copy-paste behavior and can spread insecure execution practices into production use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The example unassign command uses npx @openant-ai/cli@latest tasks unassign ... --json, encouraging copy-paste of a supply-chain-risky, state-changing operation. In this skill's context, that can directly impact task ownership and authenticated account actions if the package is compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.