Back to skill

Security audit

Find Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a skill-discovery helper, but it encourages broad activation and unattended global installation of third-party skills.

Review any skill source before installing it, avoid global installation unless you truly want it available across sessions, and do not use skipped-confirmation install commands for untrusted or newly discovered packages. This does not show malicious behavior, but it should be read carefully before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:92
Finding

Unpinned Third-Party CLI Execution with Unattended Global Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 92
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

bash
npx skills add <owner/repo@skill> -g -y

Technical Analysis

The skill directs the agent to invoke the unpinned npm package skills through npx and use it to install a skill obtained from GitHub or another external source. If the CLI is not already available locally, npx may retrieve and execute the package version resolved by the registry at runtime.

The command provides no exact CLI version, integrity hash, source allowlist, or mandatory package review. The -g option installs the selected skill globally at user level, increasing its scope beyond the current project. The -y option suppresses confirmation prompts, removing an opportunity to inspect the resolved source and installation behavior.

Consequently, security depends on mutable external components: the npm package resolved as skills, the package registry, the repository owner, and the selected skill contents. Compromise, dependency confusion, typosquatting, repository takeover, or a malicious search result could introduce executable code or hostile agent instructions.

Attack Path

  1. A user asks the agent to locate a skill for a specialized task.
  2. The agent invokes the unpinned npx skills CLI, which may download and execute registry-provided package code.
  3. Search results identify an attacker-controlled or compromised external skill.
  4. The agent runs npx skills add <owner/repo@skill> -g -y.
  5. Installation proceeds globally at user scope without an interactive confirmation step.
  6. Malicious install-time code could execute with the invoking user's privileges, or hostile skill instructions could influence subsequent agent activity.

Impact Assessment

Successful exploitation could execute code with the permissions of the user running the agent and in ...[truncated 557 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the Skills CLI to an exact, reviewed version rather than invoking an unversioned package, for example by using an approved version and validating its lockfile and integrity metadata.
  2. Separate discovery from installation. Search results should only be presented to the user until the exact repository, revision, and skill contents have been reviewed.
  3. Require explicit informed confirmation immediately before installation. Remove -y so that source and scope can be checked before changes are made.
  4. Default to project-local installation rather than -g. Global installation should require a separate explanation and explicit opt-in.
  5. Pin external skills to reviewed immutable commit hashes or signed releases instead of mutable branches or unqualified repository references.
  6. Restrict installation to an allowlist of trusted owners and repositories, and verify repository ownership and provenance.
  7. Inspect downloaded manifests, skill instructions, scripts, lifecycle hooks, and transitive dependencies before execution.
  8. Run installation in a sandbox with minimal filesystem, network, credential, and process permissions. Disable package lifecycle scripts where they are unnecessary.
  9. Record the resolved package version, source revision, integrity digest, and installation scope for later auditing.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly recommends npx skills add <owner/repo@skill> -g -y, which installs external packages globally and suppresses confirmation prompts, but it does not require a clear warning about system modification, trust, or code-execution risk. This can lead users or agents to perform unattended installation of third-party code with persistent effects, materially increasing the likelihood and impact of compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The metadata description says the skill should be used whenever users ask broad questions like 'how do I do X' or 'can you do X', which overlaps heavily with ordinary assistance requests. Over-broad activation can route many unrelated conversations into a skill that recommends external package discovery and installation, increasing the chance of unnecessary exposure to untrusted code sources.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'When to Use This Skill' section defines broad and ambiguous triggers without clear boundaries, making accidental activation likely. In this skill’s context, accidental activation is security-relevant because it steers routine user interactions toward third-party package search and installation workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning an exact package/version, which allows execution of whatever package version is current at runtime. Because npx can fetch and run remote code, this creates a supply-chain risk if the package is updated maliciously, compromised, or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

This command reference uses unpinned npx skills, which can download and execute an unexpected package version at invocation time. In a skill whose purpose is discovery and installation of third-party extensions, that increases supply-chain exposure substantially.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The unpinned npx skills add <package> instruction can result in running arbitrary updated package code from the registry. Since the command is also used to install further external content, compromise of the bootstrap CLI could cascade into broader system modification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

Using npx skills check without version pinning means the invoked code is not stable or reviewable over time. An attacker controlling or hijacking the package distribution could turn a benign maintenance step into code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

This update command relies on an unpinned npx package, exposing users to supply-chain compromise during routine update flows. Because updates inherently modify installed components, combining them with floating remote execution is risky.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The example search command uses npx skills without an exact version, so users may execute a different package revision than intended. This is a real security issue because npx is not merely documentation text here; it is an operational instruction to run remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The example command shown to users is unpinned and therefore susceptible to package substitution or malicious updates. In this context, the skill is intended to be copied verbatim by users, making the risk practically exploitable rather than theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

This install example uses npx skills add without pinning the CLI version, allowing runtime retrieval of mutable code. Because the command is an installation action, successful exploitation could lead to persistent compromise via malicious skill installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The learn-more/install flow still depends on the same floating npx skills bootstrap, so users are exposed to supply-chain risk at the moment of execution. The danger is amplified by the skill’s role as a discovery gateway to additional third-party packages.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The guidance presents npx skills add as a normal install path but does not pin the package version, leaving execution behavior mutable. This undermines reproducibility and opens a path for remote code execution through package compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The command shown for installing a skill uses the same unpinned npx pattern, so users may execute unreviewed code from a changed package version. Since this step installs system capabilities, a malicious package could gain broad access or persistence.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This instruction combines unpinned npx execution with -g -y, meaning remote code is fetched and a global install proceeds without confirmation. That significantly increases exploitability because it can lead to unattended, persistent system modification if the package or target skill is malicious or compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The suggestion to initialize a skill via bare npx skills init still relies on executing a mutable remote package. Even developer-oriented setup commands can be abused if the package distribution is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

This final example again references unpinned npx skills, preserving the same supply-chain execution risk throughout the document. Repetition across the skill makes unsafe execution patterns more likely to be copied broadly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.