Back to skill

Security audit

skroll

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Skroll deck workflow, but it repeatedly requires unpinned npm CLI execution for authenticated actions, uploads, publishing, and deletion.

Review this before installing. The Skroll functionality is disclosed and purpose-aligned, but run the CLI only from a reviewed pinned version or locked local install, use least-privilege/revocable Skroll credentials, and be deliberate about which local files are passed with `@file` arguments or which deck operations delete or publish content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Execution of an Unpinned Third-Party npm CLI

Content
View full analysis
Remediation
View remediation
instructions ``` 2. Prefer declaring the CLI in a project `package.json`, committing the corresponding lockfile, and installing dependencies with: ```bash npm ci ``` Invoke the lockfile-resolved local executable afterward. 3. Verify package integrity and provenance during installation. Use npm integrity metadata, trusted publishing provenance where available, and an approved registry. 4. Review each intended CLI upgrade before changing the pinned version. Automated dependency updates should require security review and test validation. 5. Run the CLI with least privilege in an isolated environment. Limit filesystem access, environment variables, and network destinations to those required by the task. 6. Provide Skroll credentials only to the individual command that requires them rather than exporting them broadly into a long-lived shell environment. Use narrowly scoped and revocable credentials where supported. 7. Document the expected package version and checksum so operators can detect unexpected dependency changes before execution. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (27)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

from https://skrollai.com/app/settings/integrations and export it:

bash
export SKROLL_API_KEY=sk_…      # or SKROLL_TOKEN=<OAuth access token>

If a browser is available, log in once (PKCE, no API key needed), then confirm:

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The manifest-level description references npx @skrollai/cli without a version pin, encoding insecure execution guidance into the skill metadata itself. This increases the chance that automated systems or users will adopt dynamic package execution as the canonical invocation method.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to run npx @skrollai/cli without a version pin, which causes code to be fetched and executed at runtime from the package registry. If the package is compromised, typosquatted, or a malicious update is published, the agent could execute unreviewed code with the user's local permissions and network access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line directs the agent to execute an unpinned npx @skrollai/cli instructions command. Because npx resolves the latest matching package by default, this creates a supply-chain execution path where arbitrary updated package code runs before any trust decision is made.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The login flow uses npx @skrollai/cli login without a version pin, so authentication is performed by code fetched dynamically at execution time. A compromised package could steal tokens, browser callback data, or other credentials during the login process.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

npx @skrollai/cli whoami is another unpinned runtime package execution. While lower risk than login itself, it still executes remote package code and could be abused as part of a supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command reference again relies on unpinned npx @skrollai/cli. Because this is repeated in the main usage section, the skill normalizes insecure package execution patterns and increases the chance of users repeatedly running unreviewed code from the registry.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This command example invokes an unpinned remote package. Any compromise of the package or its publication path would grant code execution in the user's environment before deck-listing logic runs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This create_deck example uses an unpinned npx package, exposing users to supply-chain execution risk. Although the task itself is non-destructive, the execution context may still include user files, tokens, and network access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Starting from another deck via an unpinned npx invocation still runs arbitrary package code from the registry at execution time. The risk stems from code execution, not from the deck operation itself.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The template creation command is another instance of unpinned registry-sourced code execution. Repetition throughout the skill broadens the attack surface because any user following examples may invoke different package versions over time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

set_deck_content uploads local files, and using it through an unpinned npx package is particularly dangerous because a compromised CLI could exfiltrate the referenced source files or adjacent filesystem data. The skill context increases risk because agents may pass proprietary presentation content through these commands.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

get_deck via unpinned npx executes remote code with access to returned data and local credentials. If the package is compromised, it could harvest account metadata or tokens while appearing to only inspect a deck.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The update_deck example again depends on unpinned runtime package resolution. Because these commands may operate on private organizational content, a malicious package update could leak metadata or alter deck settings unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This delete command uses unpinned package execution, combining supply-chain risk with a destructive operation. A malicious or compromised package could silently delete or modify more content than intended, or use the command as a cover for other harmful actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Even version-management commands executed through unpinned npx carry remote code execution risk. The danger is contextual because these operations often touch valuable historical content and may run in authenticated sessions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The help command still causes execution of unpinned package code. Users may assume help output is harmless, but the code required to display help has the same local execution privileges as any other command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line explains instructions output but still references the unpinned CLI. Because the skill repeatedly emphasizes running this command first, it effectively makes unreviewed package execution the first step in the workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The template listing example uses unpinned npx, preserving the same supply-chain risk pattern. The prevalence of this pattern across the document increases likelihood of exploitation through routine use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This deck creation example again executes unpinned package code. Since it may interact with organizational assets, a compromised package could tamper with content or leak identifiers during normal operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This set_deck_content example passes a local file into an unpinned CLI, magnifying the impact of a supply-chain compromise because proprietary source material is directly available to the executed code. In this skill context, user-authored decks may contain sensitive business data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The template creation example continues the unpinned npx pattern. Although the action is ordinary, the underlying issue remains arbitrary registry code execution with user privileges.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This line again instructs users to submit a local file to an unpinned CLI, creating both code execution and potential data exfiltration risk. The combination of local file access and authenticated API access raises the practical severity.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The npx skills add hamburgerlabs/skroll installation command is also unpinned, so it can fetch and execute changing code from the registry. This expands the supply-chain exposure beyond the Skroll CLI itself to the skills toolchain.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.