Back to skill

Security audit

agent-runlog

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent command-logging helper, with a real but disclosed and purpose-aligned dependency risk from using an unpinned npm CLI.

Before installing, consider pinning @builtbyecho/agent-runlog to a reviewed version or using a lockfile-managed local install. Avoid wrapping destructive commands without explicit approval, and keep .agent-runs logs local when command output may contain private data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party npm Package Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–15, 25, and 44–48
Vulnerability Type: Supply-chain exposure caused by executing an unpinned npm package
Risk Level: Medium

Complete Code Snippet

bash
npx @builtbyecho/agent-runlog -- npm test
npx @builtbyecho/agent-runlog -- npm run lint
npx @builtbyecho/agent-runlog -- npm run build
bash
npx @builtbyecho/agent-runlog --json -- npm test > run.json
bash
npx @builtbyecho/agent-runlog -- <command> [args...]
npx @builtbyecho/agent-runlog -o .agent-runs/lint -- npm run lint
npx @builtbyecho/agent-runlog --cwd ./subproject -- npm test
npx @builtbyecho/agent-runlog --quiet -- npm test

Technical Analysis

The Skill repeatedly instructs the Agent to execute @builtbyecho/agent-runlog through npx without specifying an exact, reviewed version. If the package is not already available locally, npx may resolve and download the package from the configured npm registry before executing it. The effective implementation can therefore change after this Skill has been audited.

This creates a third-party supply-chain trust boundary. A compromised publisher account, malicious package release, registry compromise, or compromised transitive dependency could introduce arbitrary behavior without requiring changes to SKILL.md. The downloaded package and relevant npm lifecycle behavior execute with the permissions of the user running the Agent.

The repository contains no evidence that the named package is currently malicious. The confirmed issue is the unsafe, unpinned execution model rather than a confirmed malicious payload.

Attack Path

  1. An attacker compromises the npm publisher, package release process, registry resolution path, or a transitive dependency.
  2. The attacker publishes a malicious version under the expected package name or injects malicious code into its dependency chain.
  3. The Agent follows the documented workflow and invokes `npx @builtbyecho ...[truncated 1094 chars]
Remediation
View remediation

Remediation Suggestions

  1. Select and audit a specific release of @builtbyecho/agent-runlog.

  2. Pin the package to an exact version rather than relying on registry resolution of the current release.

  3. Record the dependency in a project manifest and commit a lockfile with integrity hashes.

  4. Install dependencies using a lockfile-enforcing command such as npm ci.

  5. Invoke only the locked local binary, for example:

    bash
    npx --no-install agent-runlog -- npm test
    
  6. Configure npm to use an approved registry and apply organizational package allowlisting where available.

  7. Review the package's lifecycle scripts and transitive dependencies before adoption.

  8. Use automated dependency monitoring and require review before updating the pinned version.

  9. Run the utility in a constrained environment with minimal filesystem, network, environment-variable, and credential access.

  10. Document the expected package version, source registry, and integrity information directly in the Skill or associated installation instructions.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs users to execute npx @builtbyecho/agent-runlog without pinning an exact package version. Because npx resolves and may fetch the latest published package, a future compromised or malicious release could be executed implicitly, creating a software supply-chain risk in a context that directly runs shell commands.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This invocation uses npx with an unpinned package name, which allows whatever version is current at execution time to run. In a skill whose purpose is to wrap arbitrary shell commands, that increases the blast radius of a compromised upstream package because users are encouraged to run it repeatedly in development environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The command references an unversioned npm package through npx, which is a classic source of supply-chain exposure. If the package owner account, dependency chain, or latest release is compromised, users following this skill could execute attacker-controlled code locally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The automation example also relies on an unpinned npx package, so non-interactive scripts may fetch and execute an unexpected version. Automation contexts are especially sensitive because they may run in CI or privileged developer environments, potentially exposing tokens, source, or build artifacts if the package is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This reusable command template normalizes running an unpinned package via npx, which embeds a supply-chain hazard into all downstream uses of the skill. Since the tool is intended to wrap arbitrary commands and capture logs, a compromised package could observe command arguments, outputs, environment variables, or repository state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The output-directory example still invokes a floating package version through npx, preserving the same supply-chain execution risk. Because users may trust this as a routine diagnostic wrapper, they may run it around sensitive builds or tests without realizing the package version is not fixed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Using --cwd with an unpinned npx package is still vulnerable to executing an unintended upstream release. The context can make this slightly more dangerous because the command may be run against subprojects with distinct secrets, configs, or repositories that a compromised wrapper could inspect.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The quiet-mode example continues to rely on an unpinned package fetched by npx, so users may execute changing code over time with no explicit review. In this skill, that is materially relevant because the package sits between the user and arbitrary shell commands, giving it access to command execution context and log data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.