Back to skill

Security audit

Aero

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent AEO operations guidance, but it includes high-impact WordPress production editing, weak credential handling guidance, unpinned runtime package execution, and inconsistent memory instructions that users should review before installing.

Install only if you need Aero to coordinate AEO monitoring and are comfortable enforcing operational controls yourself. Pin or preinstall the audit tool instead of using mutable `npx`, keep WordPress MCP credentials out of committed project files, use least-privilege separate staging and production accounts, require backups and explicit human approval before any production edit or delete action, and avoid storing client/project facts in durable agent memory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/orchestration.md:15
Finding

Unpinned Third-Party Package Is Downloaded and Executed Through npx

Content
View full analysis
" --format json ``` The same unpinned package is invoked for page audits: ```bash npx @ainyc/aeo-audit "" --format json npx @ainyc/aeo-audit "" ``` ### Technical Analysis The documented workflows invoke `@ainyc/aeo-audit` through `npx` without specifying an exact package version, integrity hash, lockfile, or trusted local installation. If the package is not already installed, `npx` can retrieve the latest matching version from the configured npm registry and execute it immediately. This creates a supply-chain risk because the effective executable can change after this Skill has been reviewed. A compromised publisher account, malicious package release, registry compromise, or unsafe registry configuration could cause arbitrary package lifecycle scripts or runtime code to execute under the agent operator's account. Although no malicious dependency is bundled in this project, the documented execution method does not provide reproducible or integrity-verified dependency resolution. ### Attack Path 1. An attacker compromises the npm publisher account, package distribution process, or registry used to resolve `@ainyc/aeo-audit`. 2. The attacker publishes a malicious package version under the expected package name. 3. An operator or agent follows one of the workflows in `references/orchestration.md`. 4. `npx` resolves and downloads the mutable package version because no exact version or local-only restriction is specified. 5. Package lifecycle scripts or application code execute with the privileges of the user running the workflow. 6. The malicious code can access files, environment variables, locally available credentials, and network resources permitted to that user. ### Impact Assessme ...[truncated 672 chars]
Remediation
View remediation
"" --format json ``` 2. Prefer installing the dependency through a committed lockfile that records package integrity metadata. 3. Run the already installed binary with `npx --no-install` so the workflow fails rather than downloading an unexpected package: ```bash npx --no-install aeo-audit "" --format json ``` 4. Configure npm to use an explicitly trusted registry and review project-level and user-level npm configuration for registry overrides. 5. Verify package provenance, publisher ownership, release signatures where available, and integrity hashes before upgrades. 6. Execute the audit package in a restricted environment with minimal filesystem access, sanitized environment variables, and limited network permissions. 7. Apply the same hardened invocation to all occurrences at lines 15, 29, and 55. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/wordpress-elementor-mcp.md:24
Finding

Reusable WordPress Basic Authentication Credentials Are Stored in Project Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (9)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as an AEO analysis/orchestration tool, but it explicitly includes a reference for editing WordPress pages through an Elementor MCP integration. That expands the capability from read-only analysis into direct modification of client assets, which increases the risk of unauthorized or insufficiently reviewed changes if an agent follows the documentation too broadly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Direct WordPress editing is not clearly justified by the skill's stated purpose of AEO monitoring and orchestration, creating a privilege/scope mismatch. In an agent setting, this can cause an operator or autonomous workflow to treat destructive or state-changing actions as in-scope, raising the chance of accidental content changes, site defacement, or modification without proper authorization.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/aeo-discovery.md (reported line 119)May include surrounding context.

md
1. A one-line headline naming the dominant bucket.
2. The top 2-3 wasted-surface queries (call `canonry_discover_session_get` to fetch them — don't guess).
3. The top 1-2 recurring `direct-competitor` domains worth tracking, ignoring one-hit domains unless the operator asks for the full long tail. If a recurring `editorial-media` domain stands out, mention it separately as a placement opportunity — not a competitor.
4. A single recommended next step. Examples: "preview and promote cited + aspirational findings (`cnry discover promote preview`, then `cnry discover promote`)", "the wasted-surface set warrants a content plan around X before tracking", "the aspirational set is greenfield — pick the 3 with highest commercial intent and write content".

Do not recommend "promote everything" as the default. The safe path is: inspect session detail, preview promotion candidates, then promote the default cited + aspirational set. Escalate `wasted-surface` to tracking only when the operator deliberately chooses that tradeoff.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The workflow invokes npx @ainyc/aeo-audit without pinning an exact package version, so execution may pull whatever version is currently published at runtime. That creates a supply-chain risk: a compromised maintainer account, malicious new release, or breaking update could cause unreviewed code to run in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This step again uses npx with an unpinned package reference, allowing a mutable upstream package version to be executed during regression-response operations. Because this workflow is likely triggered automatically after incidents or webhooks, it increases the chance that unreviewed third-party code runs in a sensitive operational context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The content-gap workflow also references an unpinned npx package, exposing the agent to dependency substitution or malicious-update risk whenever the diagnostic audit is run. In an orchestration skill with persistent memory and recurring analyses, repeated execution broadens exposure and could let a bad package affect multiple projects over time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The playbook explicitly instructs the agent to persist regression events and diagnoses to memory, which can include client-related operational data such as queries, providers, dates, and evidence. Without any guardrails around consent, minimization, retention, or redaction, this creates a real privacy and data-governance risk because sensitive client activity may be stored invisibly and reused beyond the immediate task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to read this skill 'when asked to produce a client-facing summary,' which is a broad activation condition rather than a narrowly scoped trigger. Because it does not define specific trigger phrases, exclusions, or context constraints, the skill could be invoked for many ordinary summary requests beyond weekly/monthly AEO reporting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide explicitly instructs replaying changes on production after staging validation, but it does not include a clear warning that production edits can cause irreversible content loss, layout breakage, or downtime if tools are misused. In an agent skill context, operational instructions can be followed automatically, so omission of guardrails increases the chance of unsafe destructive actions against a live site.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.