Back to skill

Security audit

Style Transfer(风格迁移)

Security checks for vulnerabilities and agentic risk

Overview

The skill does a coherent style-transfer job, but it tells agents to run an unpinned third-party npx tool that can download and execute changing code with the user's local privileges.

Use this only in a disposable or version-controlled workspace. Pin and review the `designlang` package before running it, inspect generated files before importing them, and review diffs before allowing changes to project styles, Tailwind config, HTML, or font loading.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Package Execution via npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–21
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
npx designlang https://target-website.com/ --full

The documented alternative is also vulnerable:

bash
npx designlang https://target-website.com/

Technical Analysis

The skill directs the agent to execute designlang through npx without specifying a reviewed package version, validating package integrity, enforcing a trusted registry, or using a lockfile. If the package is not already available locally, npx can retrieve it from the configured npm registry and execute its CLI code.

Consequently, the code that runs may differ from the code originally reviewed. A compromised package release, malicious registry configuration, dependency-confusion condition, or loss of control over the package could turn this workflow into arbitrary code execution. Package lifecycle scripts and the CLI itself may run with the permissions of the user operating the agent.

This finding concerns an unsafe supply-chain execution mechanism. The audited file does not establish that the current designlang package is malicious.

Attack Path

  1. An attacker compromises the resolved designlang package, one of its dependencies, its publisher account, or the registry through which it is resolved.
  2. The attacker publishes a malicious version or causes the package name to resolve to attacker-controlled content.
  3. A user invokes the style-transfer skill.
  4. The agent runs one of the unpinned npx designlang commands.
  5. npx downloads the currently resolved package and executes its lifecycle or CLI code.
  6. The malicious code runs with the agent user's privileges and can access resources available to that account.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the account running the agent. Depending on that account's permissions and e ...[truncated 603 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin designlang to an exact version that has been reviewed rather than resolving the latest available release:
bash
npx --yes designlang@<reviewed-exact-version> https://target-website.com/
  • Record and verify the expected package integrity hash through a lockfile or an equivalent trusted package-verification mechanism.
  • Require installation from an explicitly trusted npm registry and review .npmrc settings before execution.
  • Prefer an audited, preinstalled dependency or a vendored internal tool over runtime package retrieval.
  • Disable npm lifecycle scripts where compatible with the reviewed tool:
bash
npm_config_ignore_scripts=true npx --yes designlang@<reviewed-exact-version> https://target-website.com/
  • Run the extraction utility in a sandbox or container with:
    • No access to unrelated credentials or sensitive directories.
    • Read-only access to source files where possible.
    • A dedicated writable output directory.
    • Restricted outbound network access.
  • Review the pinned package and its transitive dependencies before updating the approved version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill when the user says phrases like “把 XX 网站的样式应用到我的项目” or “用 Y 的风格重新设计,” which are common, high-level requests that could overlap with many ordinary design or coding tasks. The file does not provide explicit boundaries, exclusions, or negative examples clarifying when the skill should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells users to run a third-party extraction command against a target website and notes that outputs are written to local directories, but it does not clearly warn about external network access, remote content processing, or filesystem writes. In this context, that omission is dangerous because users may unknowingly execute code that contacts arbitrary hosts and stores potentially untrusted artifacts locally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs use of npx designlang without pinning an exact version, which causes execution of whatever package version is current at runtime. That creates a supply-chain risk: a compromised or malicious update could execute arbitrary code on the analyst's machine while also accessing network resources and local files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This is a second unpinned invocation of npx designlang, so the same supply-chain issue applies independently here. Because npx may download and execute remote code on demand, the skill effectively delegates trust to the latest published package version without review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides step-by-step instructions to replace styling variables, edit framework configs, inject fonts, and create/import new files, but it does not warn that these operations may overwrite existing project configuration or break builds. In a code-modifying skill, omission of change-scope and backup guidance can cause unintended destructive edits and supply additional opportunities for persistence of unreviewed third-party-derived content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The troubleshooting guidance again recommends npx designlang without version pinning, reinforcing unsafe execution patterns throughout the skill. Repetition increases the chance users will run remote code casually, making compromise via package takeover or malicious release more plausible.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The example conversation normalizes running an unpinned third-party package against an arbitrary website, which is especially risky because examples are often copied verbatim. This can expose the local environment to arbitrary code execution from a malicious or compromised package release.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.