Back to skill

Security audit

Click Driven Presentation

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently builds a local click-through presentation project, with disclosed file writes and npm installs plus some non-malicious hardening gaps.

Install only if you are comfortable with a skill that creates a local web project and may run npm install. Use a fresh target directory, avoid --force unless you intend to overwrite files, prefer the default theme, and use --no-install if you want to inspect the scaffold before dependencies are installed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scaffold.sh:22
Finding

Theme Identifier Path Traversal Allows Files Outside the Theme Directory to Be Copied

Content
View full analysis
/dev/null; exit 0 ;; --*) echo "Unknown option: $arg" >&2; exit 1 ;; *) TARGET="$arg" ;; esac done THEME_TOKENS="$SKILL_DIR/themes/$THEME/tokens.css" if [ ! -f "$THEME_TOKENS" ]; then echo "Theme not found: $THEME (looked for $THEME_TOKENS)" >&2 echo "Available themes:" >&2 ls "$SKILL_DIR/themes" 2>/dev/null >&2 || true exit 1 fi ``` The resulting path is later copied into the generated project: ```bash cp "$THEME_TOKENS" "$TARGET/src/theme/tokens.css" ``` ### Technical Analysis The value supplied through `--theme` is interpolated directly into a filesystem path. The script does not restrict the value to a valid theme identifier, reject path separators or `..` components, or verify the canonical source path remains under `$SKILL_DIR/themes`. Shell quoting prevents command injection, but it does not prevent filesystem path traversal. A value containing traversal components can resolve outside the intended theme directory. The regular-file check only establishes that the resolved path exists; it does not establish that it belongs to an authorized theme. Exploitation is constrained by the hardcoded `tokens.css` suffix. The attacker must identify or arrange a reachable path ending in `tokens.css`. Nevertheless, if such a path exists, the script can copy that file into the generated presentation. ### Attack Path 1. An attacker or untrusted automation controls the arguments passed to `scaffold.sh`. 2. The attacker identifies a readable file outside the theme directory whose path ends in `tokens.css`. 3. The attacker supplies a traversal value, for ex ...[truncated 1094 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Prefer selecting themes from an enumerated list of directories directly under `$SKILL_DIR/themes`. 3. Canonicalize the theme root and requested file, then verify containment: ```bash THEMES_ROOT="$(realpath "$SKILL_DIR/themes")" THEME_TOKENS="$(realpath "$SKILL_DIR/themes/$THEME/tokens.css")" case "$THEME_TOKENS" in "$THEMES_ROOT"/*) ;; *) echo "Theme path escapes the authorized theme directory." >&2 exit 1 ;; esac ``` 4. Retain the regular-file check after canonicalization. 5. Add regression tests covering `../`, absolute paths, repeated separators, symbolic links, and valid theme identifiers. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/scaffold.sh:57
Finding

Unpinned npm Dependency Resolution Creates a Non-Reproducible Supply-Chain Risk

Content
View full analysis
"$TARGET/package.json" <<'FILE' { "name": "presentation", "private": true, "version": "0.0.0", "type": "module", "scripts": { "dev": "vite", "build": "vite build", "preview": "vite preview", "typecheck": "tsc --noEmit" }, "dependencies": { "react": "^18.3.1", "react-dom": "^18.3.1" }, "devDependencies": { "@types/react": "^18.3.12", "@types/react-dom": "^18.3.1", "@vitejs/plugin-react": "^4.3.4", "typescript": "^5.6.3", "vite": "^6.0.5" } } FILE ``` The script then performs a live dependency resolution and installation: ```bash if [ "$DO_INSTALL" -eq 1 ]; then echo "Installing dependencies in $TARGET ..." (cd "$TARGET" && npm install) fi ``` ### Technical Analysis The scaffold does not provide a reviewed `package-lock.json`, and dependency versions use caret ranges. Consequently, each invocation of `npm install` can resolve a different set of direct and transitive package versions. npm installation may also execute package lifecycle scripts. If a newly allowed direct version or a transitive dependency is compromised, malicious package code could run under the account invoking the scaffold. The audited project does not itself contain a malicious package or remote payload; the issue is that the effective dependency graph is mutable after review. ### Attack Path 1. The scaffold is audited while the npm packages in the currently resolved dependency graph are benign. 2. At a later time, an allowed package release or transitive dependency is compromised, or an upstream maintainer account publishes malicious code. 3. A user runs the scaffold without `--no-install`. 4. `npm install` reso ...[truncated 1063 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/scaffold.sh (reported line 468)May include surrounding context.

sh
npm run typecheck      # run before reporting a scene "done"

Before building real scenes, delete the demo:
  rm -rf "$TARGET/src/scenes/01-example"
  # then remove the Example import + entry from src/registry/scenes.ts

Build one scene per folder (NN-id), each with its own steps.ts and CSS prefix.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog states 'English-only skill text' as a fixed constraint. Under the policy rules, forcing a specific language without user opt-in or a clearly justified regional/compliance reason is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The instruction to run npx tsc --noEmit invokes a package runner without pinning a specific toolchain version. In environments where TypeScript is not already installed locally, npx may fetch and execute code from the registry at runtime, creating a supply-chain risk and reducing build reproducibility. In this skill context, the command is presented as a required completion step, which increases the chance an agent will execute it automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This shell script performs extensive file writes into the target directory, and the --force option bypasses the non-empty-directory safety check. While the usage text mentions --force, there is no runtime confirmation prompt or prominent warning immediately before the writes occur, which can lead to unintended overwrites in an existing project directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.