Back to skill

Security audit

Verify Submission

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its OpenAnt review purpose, but it gives an agent fund-affecting authority through unpinned runtime tools and limited confirmation boundaries.

Review this skill carefully before installing. Use it only in a constrained environment, prefer a pinned and vetted OpenAnt CLI version instead of @latest, and require explicit confirmation before accepting applicants, rejecting submissions, approving work, or releasing escrow. Treat downloaded submissions as untrusted and inspect them read-only unless sandboxed and approved.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:6
Finding

Mutable and Unpinned Packages Are Executed Through npx

Content
View full analysis
--json ``` ```bash npx @openant-ai/cli@latest tasks review \ --application \ --accept \ --comment "Great portfolio! Looking forward to your work." \ --json ``` ```bash npx @openant-ai/cli@latest tasks verify \ --submission \ --approve \ --comment "Perfect work! Exactly what we needed." \ --json ``` From `references/skills-ecosystem.md`: ```markdown - **[skills.sh](https://skills.sh/)** — Open Agent Skills Directory. Install: `npx skills add --skill ` - **[ClawHub](https://clawhub.ai/)** — Skill dock for agents. Install: `npx clawhub@latest install ` ``` ```bash # PDF handling npx skills add anthropics/skills --skill pdf # Code review npx skills add skillcreatorai/ai-agent-skills --skill code-review # Find skills for a task npx skills add vercel-labs/skills --skill find-skills ``` ### Technical Analysis The skill repeatedly instructs the agent to execute `@openant-ai/cli@latest` through `npx`. The `@latest` tag is mutable, so the code executed during a future invocation is not necessarily the version that existed when this skill was audited. If the package publisher account, registry, release p ...[truncated 3257 chars]
Remediation
View remediation
install npx --yes skills@ add --skill ``` 3. Pin repository-based skills to immutable commit hashes or signed release artifacts rather than branches, tags that can be moved, or repository names alone. 4. Prefer a preinstalled and independently reviewed CLI over downloading code during each skill invocation. Manage it through a lockfile and a controlled build or deployment process. 5. Verify package integrity using registry integrity metadata, trusted checksums, provenance attestations, or cryptographic signatures. Record the expected digest alongside the approved version. 6. Disable or carefully review dependency lifecycle scripts during installation where feasible. Install dependencies in a restricted build environment rather than in the agent's operational environment. 7. Run the OpenAnt CLI with least privilege in an isolated environment. Restrict filesystem access, environment-variable exposure, and outbound network access to the minimum required endpoints. 8. Separate read-only review operations from state-changing commands. Require explicit user confirmation immediately before application acceptance, rejection, submission approval, or any operation that releases escrow. 9. Maintain an approved dependency inventory and periodically review pinned updates before changing versions. Re-audit the resolved package and its transitive dependency tree for each upgrade. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (27)

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The manifest's allowed-tools entries all authorize npx @openant-ai/cli@latest ..., which bakes a mutable remote package reference directly into the skill's execution policy. This is more severe than a stray example because it governs what the agent is permitted to run and normalizes on-demand execution of unpinned code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The skill invokes npx @openant-ai/cli@latest in its allowed-tools manifest, which fetches and executes whatever package version is current at runtime rather than a reviewed, immutable release. If the npm package is compromised, a bad release is published, or a dependency chain is hijacked, the agent may execute attacker-controlled code with the permissions of the Bash tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The authentication check command uses npx @openant-ai/cli@latest, so even a read-only status operation requires downloading and executing the newest published package at runtime. That expands the trust boundary to the npm registry and package maintainers for every run, creating a software supply-chain execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The application-listing command executes an unpinned @latest package from npm. Although the business action is benign, the mechanism still allows arbitrary code from a newly published or compromised package to run in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The application-accept command relies on npx ...@latest, turning a sensitive state-changing operation into a supply-chain risk. Because this command can assign work and potentially affect funds/workflow, compromised package execution here is more dangerous than a purely informational command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The reject-application workflow also executes the newest npm package at runtime. A malicious or compromised release could run arbitrary code, alter rejection behavior, exfiltrate task/application data, or tamper with review actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The submission-details retrieval command uses @latest, so each review action depends on an unreviewed package release at execution time. This creates a classic software supply-chain vulnerability with potential code execution and data exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Listing files via an unpinned npx package allows remote code execution through package compromise before any file-review logic even begins. Given that the command may expose submission and attachment metadata, a malicious package could also exfiltrate sensitive project information.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Downloading files via npx @openant-ai/cli@latest compounds two risks: unpinned package execution and handling of untrusted user files. A compromised package could manipulate downloads, write unexpected files, or exfiltrate downloaded content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The variant that downloads to a specified directory still executes an unpinned package from npm. This exposes the host to arbitrary code execution and potentially unsafe filesystem writes by a malicious package release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Fetching presigned URLs through @latest entrusts credential-bearing operations to the latest npm release without review. A compromised package could leak URLs, task identifiers, or auth tokens, enabling unauthorized file access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The approve-submission command uses npx ...@latest for an action that can immediately release escrowed funds. If the package is compromised, the attacker gains an opportunity to execute code and potentially tamper with or spoof high-value approval operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The reject-submission command relies on the latest runtime package, exposing a sensitive workflow transition to supply-chain compromise. A malicious package could falsify status, alter comments, or exfiltrate review content and credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The example workflow includes another unpinned runtime invocation, reinforcing a pattern of executing mutable external code throughout the skill. Examples are often copied verbatim, so this increases real-world exploitation likelihood.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
| 3rd | → IN_DISPUTE | Platform arbitration opens; both sides notified |

- Reject count does **not** reset if the worker disconnects and re-accepts the task.
- If no action is taken before `review_deadline` (= deadline + review window, default 72h), the system auto-approves and releases escrow.

## Status Flow (Human Verification)

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The example command to list applications again uses @latest, perpetuating the same supply-chain execution risk. Because users and agents may follow examples directly, these instances are not merely documentation issues; they drive unsafe execution behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The example acceptance command executes a mutable npm package during a state-changing action. This could enable unauthorized code execution or workflow tampering if the package or dependencies are compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The example tasks get command continues the unsafe @latest pattern. Even read operations can leak tokens, task metadata, or system information when mediated by compromised tooling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The example file-download command couples untrusted file retrieval with unpinned package execution from npm. That raises the chance of filesystem abuse, data exfiltration, or execution of attacker-controlled code in the toolchain.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The example approve command uses an unpinned package for a fund-releasing workflow. Compromised tooling here could have direct financial and integrity consequences beyond ordinary code execution risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill explicitly authorizes autonomous execution of high-impact actions and states that downloading files requires 'no confirmation needed.' In this context, the agent can accept/reject applications, approve/reject submissions, and download untrusted deliverables without a fresh user checkpoint, increasing the risk of mistaken approvals, unintended fund release, privacy exposure, or processing of malicious content.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
- **Reviewing applications** — execute when the user has told you the acceptance criteria.
- **Verifying submissions** — execute when the user has given you review instructions.
- **Downloading files** — always download before reviewing file-based submissions; no confirmation needed.

## Additional Resources

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The timeout-handling retry guidance again depends on @latest, meaning recovery from failures still executes mutable external code. In incident conditions, operators may retry quickly and repeatedly, increasing exposure to a malicious or broken release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documentation instructs users to run npx skills add <owner/repo> --skill <skill-name> without pinning the package version for the skills CLI itself. Unpinned npx execution fetches the latest published package at runtime, which creates a supply-chain risk: a compromised or malicious future release could execute arbitrary code on the operator's machine during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The command npx clawhub@latest install <skill> explicitly tracks the latest release, which is effectively unpinned and allows code changes outside the author's control to be executed immediately by users. If the package is compromised, typosquatted, or a malicious version is published, running this command can lead to arbitrary code execution and downstream compromise of the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The example npx skills add anthropics/skills --skill pdf invokes the skills package without an exact version, so the executed code depends on whatever version is current in the registry at runtime. In a skill ecosystem document that encourages installing third-party tooling, this increases supply-chain exposure because users may execute unreviewed package updates while handling task submissions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.