Back to skill

Security audit

Framer CRM API

Security checks for vulnerabilities and agentic risk

Overview

This Framer skill is not clearly malicious, but it gives an agent broad site-changing powers with weak safeguards for destructive, code-related, and credential-handling actions.

Review this carefully before installing. Use it only for Framer projects where you are comfortable letting the agent read and mutate CMS content, project structure, code overrides, and deployment state. Provide a project-scoped API key if possible, keep it out of source control and logs, and require explicit confirmation before deletes, schema changes, page/code changes, screenshots, redirects, production deploys, or bulk operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:38
Finding

Unpinned npm Dependency Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
``` 2. Commit a reviewed `package-lock.json` and use deterministic installation: ```bash npm ci ``` 3. Where package functionality permits, prevent lifecycle scripts during installation: ```bash npm ci --ignore-scripts ``` If lifecycle scripts are required, inspect them before installation and document why they are necessary. 4. Verify package provenance and lockfile integrity before use. Review the resolved package name, version, registry source, integrity hashes, maintainers, and transitive dependency changes. 5. Run installation and API operations in a restricted environment with access only to the required project directory and Framer credentials. 6. Do not expose unrelated secrets to the Node.js process. Supply only `FRAMER_PROJECT_URL` and `FRAMER_API_KEY` for the specific operation. 7. Use a project-scoped Framer API key with the narrowest available permissions, rotate it if dependency compromise is suspected, and avoid printing it to logs or conversation output. 8. Update both installation instructions so onboarding cannot silently replace the reviewed dependency version with a newer unreviewed release. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation includes creation of custom code files and access to custom code injection slots, enabling script insertion beyond normal CMS content management. In an agent context, these capabilities can be used to alter site behavior, inject tracking or malicious code, and compromise integrity of the published site, making this substantially more dangerous than ordinary content editing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to match general site publishing or content-management requests, which may cause the skill to activate outside its safest intended context. Over-broad activation increases the risk that a powerful skill with publish/deploy and administrative capabilities is selected for ambiguous prompts, leading to unintended changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill directs checking .env and environment variables for FRAMER_API_KEY and project URL without any guardrails about secret minimization, redaction, or avoiding echoing credential values. In an agent context, this can normalize unnecessary secret access and increase the chance of credentials being exposed in logs, tool output, or responses.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a Framer CMS management capability, but the documented methods extend into broader project administration such as code files, page/node management, redirects, screenshots, and custom code access. This scope mismatch can cause the agent to take higher-privilege actions than the user reasonably expects from a CMS-focused skill, increasing the chance of unauthorized or destructive operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Including code-file creation, page manipulation, node removal, redirects, screenshots, and custom code retrieval in a CMS skill materially expands the blast radius from content editing to site modification and potential code injection. If activated in response to a routine CMS request, the skill could alter live site behavior or expose sensitive project structure beyond what the user intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The field-removal example shows schema deletion with no warning that removing fields can permanently affect collection structure and may orphan, hide, or destroy existing content workflows that depend on those fields. In the context of a CMS-management skill, schema operations are high-risk because they can impact many items at once and break downstream publishing or integrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reference documents single and bulk delete operations for CMS items without any adjacent warning, confirmation requirement, or safer usage guidance. In a skill that automates Framer CMS management, this increases the chance an agent or user will perform irreversible content deletion accidentally, especially at scale via bulk deletion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The onboarding flow directs users to place a live Framer API key into a project-local .env file, which increases the chance of accidental exposure through source control, shell history, backups, logs, editor tooling, or sharing the project directory. Although it does mention adding .env to .gitignore, it does not clearly warn that the key is sensitive, discourage storing it in the repo workspace when avoidable, or recommend safer secret-handling practices.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file documents broad project-level capabilities such as styles, code files, pages, localization, redirects, and screenshots, which exceed the skill's declared Framer CMS management scope. This scope expansion increases the chance that an agent using the skill will perform unintended non-CMS actions, weakening least-privilege assumptions and making harmful operations easier to justify through documentation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The page creation/deletion, node traversal, and screenshot functionality expose generalized site editing and content inspection features outside the declared CMS workflow. These operations can be abused to modify site structure, remove pages, enumerate project contents, or capture sensitive visual data, expanding the blast radius of the skill beyond expected CMS automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example shows page deletion via removeNode without any warning, confirmation requirement, or indication that the action is destructive. In an agent-driven workflow, omission of such safeguards can normalize unsafe deletion behavior and lead to accidental or unauthorized removal of live site content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The custom code injection section presents access to head/body injection content without warning about security and integrity implications. Even though the snippet only reads current content, normalizing this feature in a CMS-oriented skill can facilitate later misuse for persistent script injection, analytics abuse, or supply-chain style modifications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The screenshot example omits any warning that captured images may expose unpublished content, user-specific views, or other sensitive visual data. In an automated context, silent screenshotting can become a data-exfiltration or privacy risk, especially when combined with broad node traversal capabilities.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.