Back to skill

Security audit

find-skills (jimliuxinghai)

Security checks for vulnerabilities and agentic risk

Overview

This skill is for finding and installing other skills, but it uses broad triggers and recommends unpinned, global installation commands that can persistently change the user's agent environment.

Review this skill carefully before installing. Use it only when you explicitly want an agent to search for or install external skills, prefer pinned and source-verified commands, inspect any target skill first, and avoid global unattended installs unless you understand the persistent changes being made.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:23
Finding

Unpinned Third-Party CLI and Unattended Global Skill Installation

Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` ```markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts. ``` ### Technical Analysis The skill instructs the agent to execute `npx skills` without pinning the CLI to a reviewed version. Depending on the local npm environment, `npx` may download and execute the package dynamically. The effective CLI implementation can therefore differ from the version that existed when this skill was audited. The installation target is also selected from external search results and may originate from GitHub or other unspecified sources. The workflow does not require an immutable commit, version pin, checksum, signature, source allowlist, repository-ownership validation, or inspection of the downloaded skill before installation. The suggested `-g -y` flags compound the exposure: `-g` creates a persistent user-level installation, while `-y` suppresses interactive confirmation. Consequently, a compromised registry package, malicious repository, dependency-confusion package, typosquatted package, or manipulated search result could cause attacker-controlled package lifecycle code or hostile agent instructions to be ...[truncated 1486 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The metadata description defines very broad trigger phrases like 'how do I do X' and 'find a skill for X', which can cause the skill to activate for many routine requests. In this skill, over-triggering is risky because activation may lead the agent to run package-manager commands and propose installation of third-party code when the user only wanted advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation guidance uses ambiguous conditions such as 'can you do X' and 'expresses interest in extending agent capabilities' without clear boundaries. That broadness increases the chance of unnecessary skill activation and cascades into the more serious supply-chain and environment-modification behaviors described later in the file.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a specific package version, which causes code to be fetched and executed from the registry at runtime. That creates a supply-chain risk: a compromised latest release, typosquatted package, or unexpected upstream change could execute arbitrary code on the user's machine during search, install, update, or check operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command reference uses npx skills without a pinned version, so the agent may execute whatever package version is current at invocation time. In a skill whose purpose is discovering and installing further extensions, that greatly increases exposure to registry compromise or malicious package updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill suggests npx skills add <package> with no pinned CLI version, meaning the package manager binary itself is untrusted and mutable. If the skills package is compromised, the add flow could install arbitrary code or alter the environment before the user notices.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Even for check, invoking npx skills unpinned executes code obtained at runtime from the registry. While this command sounds lower risk than install, a malicious or altered CLI can still run arbitrary code locally during the check operation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

npx skills update without version pinning combines two risks: executing an unpinned remote CLI and updating installed skills from external sources. That can rapidly expand compromise impact by pulling newer malicious content into the environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The search step tells the agent to run npx skills find [query] using an unpinned remotely fetched CLI. Because the skill is designed to activate from broad user prompts, this can turn ordinary conversations into opportunities to execute mutable third-party code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example invokes npx skills unpinned, so the exact code executed depends on the latest published package rather than a reviewed version. Example commands in skills often become copy-pasted operational guidance, increasing the likelihood of unsafe execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example repeats the same unpinned npx skills pattern in a workflow that encourages discovery of third-party extensions. It is dangerous because users may trust the example and execute an unreviewed latest package plus subsequently install additional untrusted skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The changelog example still executes an unpinned package through npx, exposing the user to runtime supply-chain compromise. The benign nature of the query does not reduce the underlying risk because the danger comes from the package execution path, not the search term.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The install command shown to users is based on prior use of an unpinned CLI and promotes adding externally sourced skills. While the line itself is only a display example, it normalizes execution of mutable package-manager commands and trust in remote code sources.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This line explicitly tells the agent it can install a skill using npx skills add ... -g -y, but the npx skills binary is unpinned and thus untrusted at execution time. Because installation changes the user environment, compromise here can result in persistent malicious code or configuration changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends npx skills add <owner/repo@skill> -g -y, which both installs globally and suppresses confirmation prompts, yet it does not warn the user that this modifies their environment. This reduces transparency and user control, making accidental or malicious installation of third-party code significantly more dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The install snippet uses unpinned npx skills in the most dangerous context: global installation with suppressed prompts. An attacker controlling the CLI package or influencing the skill source could achieve code execution and persistence with minimal user visibility.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The fallback guidance still recommends npx skills init without version pinning, again relying on transient remote code execution. Although initialization seems developer-oriented, a compromised CLI could write malicious files, hooks, or scripts into the local workspace.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This final example again uses unpinned npx skills init, which can execute attacker-controlled code from the registry and create malicious project scaffolding. Repetition across the skill increases the chance that an agent will operationalize this unsafe pattern frequently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.