T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned Remote Package Execution During Setup
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a legitimate Nia integration, but it needs review because it can upload broad local code folders and database connection details to Nia and uses an unpinned setup command.
Install only if you trust Nia with the repositories, local files, manifests, saved contexts, and any database material you choose to send. Review folder contents before indexing, avoid uploading secrets, use read-only short-lived database credentials, set restrictive permissions on `~/.config/nia/api_key`, and prefer a pinned or verified setup package instead of `npx ...@latest`.
SKILL.md:17Unpinned Remote Package Execution During Setup
scripts/folders.sh:151Reusable Database Credentials Are Transmitted to a Third-Party API
scripts/folders.sh:8Local Files Are Uploaded Without Secret Filtering or Explicit Content Confirmation
SKILL.md:22API Key Setup Does Not Enforce Restrictive File Permissions
The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.
The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.
The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.
The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.
The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
Referenced artifact was not completely inspected
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`
The skill exposes commands to create, update, and delete shared context/memory records. In an agent ecosystem, this can be abused to tamper with long-lived memory, erase audit-relevant context, or poison future agent behavior through manipulated stored knowledge.
./scripts/contexts.sh semantic-search [limit] # Vector search ./scripts/contexts.sh get <context_id> # Get by ID ./scripts/contexts.sh update [title] [summary] [content] # Update context ./scripts/contexts.sh delete <context_id> # Delete context
Save env: `TAGS` (csv), `MEMORY_TYPE` (scratchpad|episodic|fact|procedural), `TTL_SECONDS`, `WORKSPACE`
This command packages a database connection string and query and sends them to a remote endpoint, which can expose credentials, internal hostnames, and sensitive query results or enable remote access patterns users may not expect. In the context of a repository/document indexing skill, adding DB ingestion materially raises the data-exfiltration risk because users may assume operations are local or limited to files.
Even for preview, the script sends database connection details and an arbitrary query to a remote service without a clear warning. That can disclose credentials and sensitive schema/data while encouraging users to treat preview as low risk, despite it crossing the same trust boundary as full ingestion.
The README instructs users to run npx nia-wizard@latest, which fetches and executes the latest package version at install time without pinning. That creates a supply-chain risk: if the package is compromised or a breaking/malicious version is published, users may execute unreviewed code during setup.
No suspicious patterns detected.