Back to skill

Security audit

Pipeworx dicebear

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its setup runs a mutable npm package and it can send personal seed text to external services without enough privacy guidance.

Review before installing. Use non-sensitive pseudonymous seeds, not emails, tokens, customer IDs, or confidential strings. Prefer a pinned reviewed version of the MCP bridge, or avoid the npx @latest configuration unless you are comfortable running newly downloaded package code locally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:54
Finding

Automatic Execution of an Unpinned npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54-61
Vulnerability Type: Supply-chain risk caused by an unpinned, automatically downloaded dependency
Risk Level: High

Vulnerable Code Snippet:

json
{
  "mcpServers": {
    "pipeworx-dicebear": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/dicebear/mcp"]
    }
  }
}

Technical Analysis

The recommended MCP configuration invokes npx with the -y option and executes mcp-remote@latest. The latest npm distribution tag is mutable and does not identify a fixed, previously audited package version. The -y option suppresses the normal installation confirmation, causing the dependency to be downloaded and executed automatically.

Consequently, the code executed when this configuration is used may differ from the code available when the skill was audited. The configuration provides no exact version pin, package integrity hash, lockfile, provenance validation, or other mechanism for detecting an altered package release.

This creates a supply-chain execution channel. Exploitation would require compromise or malicious modification of the referenced npm package, its maintainer account, the package distribution process, or another relevant dependency-resolution component.

Attack Path

  1. An attacker compromises the mcp-remote npm package, its maintainer account, or the release process associated with the mutable latest tag.
  2. The attacker publishes a malicious version and assigns or causes the latest tag to resolve to it.
  3. A user or agent activates the documented MCP configuration.
  4. npx -y downloads the package without interactive confirmation.
  5. The downloaded package executes locally under the privileges and environment of the invoking user or agent.
  6. Malicious package code can access resources available to that process.

Impact Assessment

Successful ...[truncated 567 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace mcp-remote@latest with an exact, reviewed version such as mcp-remote@x.y.z.
  2. Use a lockfile and verify the resolved package and transitive dependency versions.
  3. Validate package integrity using trusted registry integrity metadata or a separately maintained cryptographic hash.
  4. Remove -y where practical so that unexpected installation or version changes require explicit approval.
  5. Prefer a preinstalled, reviewed dependency rather than downloading executable code when the skill is activated.
  6. Document the official package source, expected publisher, reviewed version, and upgrade procedure.
  7. Run the MCP process in a sandbox with minimal filesystem, network, credential, and environment-variable access.
  8. Review and pin transitive dependencies before updating the approved version.

other

Warning
Location
SKILL.md:19
Finding

Potential Disclosure of Sensitive Avatar Seeds to External Services

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19-34
Vulnerability Type: Privacy and sensitive-data exposure through a third-party service and generated URL
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- **`generate_avatar`** — Generate an avatar URL for a given style and seed. The seed can be a username, email, or any string.
bash
curl -s -X POST https://gateway.pipeworx.io/dicebear/mcp \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"generate_avatar","arguments":{"style":"bottts","seed":"alice"}}}'

Technical Analysis

The skill explicitly allows an email address, username, or arbitrary string to be used as the avatar seed. The documented request sends that seed to gateway.pipeworx.io, an external intermediary. The example response described elsewhere in the file also places the seed in a DiceBear URL query parameter.

If a user or agent supplies personal, confidential, or otherwise sensitive text, that value can be disclosed to the gateway operator. If the returned URL contains the raw seed, it may additionally become visible to DiceBear and to systems that process or record the URL, including application logs, browser history, proxy logs, monitoring systems, caches, analytics tools, and referrer data.

The documentation contains no warning against sensitive seeds, local pseudonymization requirement, consent requirement, retention disclosure, or data-minimization guidance. HTTPS protects data in transit but does not prevent endpoint operators or downstream systems from receiving and logging the value.

Attack Path

  1. A user or agent selects an email address, internal username, customer identifier, or confidential string as the seed, as expressly permitted by the documentation.
  2. The skill sends the raw value in a POST request to gateway.pipeworx.io.
  3. The external gateway receives and may log ...[truncated 987 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not recommend email addresses, secrets, access tokens, private identifiers, or confidential text as raw seeds.
  2. Generate a deterministic pseudonymous seed locally, such as an HMAC of the original identifier using an application-controlled secret.
  3. Avoid an intermediary gateway when the avatar URL can be constructed locally using validated style and seed values.
  4. Clearly disclose every external recipient of seed data and obtain appropriate user consent before transmission.
  5. Document data retention, logging, and deletion behavior for the gateway and downstream avatar service.
  6. Prevent raw seeds from being written to application logs, analytics events, error reports, or telemetry.
  7. If seeds must appear in URLs, use non-sensitive random or pseudonymous values and configure strict referrer and logging policies.
  8. Apply input length and character restrictions to prevent accidental submission of large or inappropriate sensitive values.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill depends on curl and a remote MCP gateway, which means user-provided input will be transmitted outside the local environment. In this context, remote transmission is expected functionality rather than inherently malicious, but it still creates a data exposure risk if users assume avatar generation is local or provide sensitive seed material.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "👤"
    homepage: https://pipeworx.io/packs/dicebear
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly encourages using arbitrary seed strings such as usernames or emails, but it does not clearly warn users that those values are transmitted to remote services. Because seeds may contain personal or sensitive identifiers, this omission can cause inadvertent disclosure of user data to third-party infrastructure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

json
{
  "url": "https://api.dicebear.com/7.x/bottts/svg?seed=alice",
  "style": "bottts",
  "seed": "alice"
}

Static analysis

No suspicious patterns detected.