Back to skill

Security audit

cargo-analytics

Security checks for vulnerabilities and agentic risk

Overview

This Cargo analytics skill is mostly aligned with exporting and measuring Cargo data, but it needs review because it installs a mutable CLI and includes workspace-changing rerun commands without strong safeguards.

Install only if you trust the Cargo CLI publisher and can control the CLI version. Prefer a pinned CLI release, use a read-only or least-privilege Cargo token for analytics, treat generated files and signed URLs as sensitive, and require explicit confirmation before any batch rerun or other workspace-changing command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Executable npm Dependency

Content
View full analysis
(CI) cargo-ai whoami # confirm the active workspace before any write ``` The troubleshooting guide repeats the unsafe installation guidance: ```markdown | `command not found: cargo-ai` | CLI not installed or not in PATH | Run `npm install -g @cargo-ai/cli` or prefix with `npx @cargo-ai/cli` | ``` ### Technical Analysis The Skill installs `@cargo-ai/cli@latest` or executes the package through `npx` without an exact version or integrity constraint. The `latest` npm distribution tag is mutable, so the effective executable can change after the Skill has been reviewed. A global npm installation also increases exposure because package installation scripts and the installed executable run with the invoking user's permissions and remain available outside the immediate Skill invocation. The project contains no lockfile, checksum, integrity metadata, or local implementation that would allow the reviewed Skill to guarantee which CLI code will execute. The package name and declared GitHub organization are internally consistent, and the audit found no evidence that the current package is malicious. The vulnerability is therefore an unsafe supply-chain trust model rather than proof of an active malicious dependency. ### Attack Path 1. A user or Agent loads the Skill on a sy ...[truncated 1298 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:239
Finding

Workspace-Mutating Batch Creation Exceeds the Declared Analytics Scope

Content
View full analysis
\ --data '{"kind":"recordIds","recordIds":["id1","id2","id3"]}' ``` ``` ### Technical Analysis The Skill explicitly defines its scope as measurement and export and describes its purpose as answering “what happened” and “give me the data.” However, the cited instruction invokes `orchestration batch create`, which is a state-changing operation rather than an analytics or export operation. Creating a batch can launch workflow execution against selected records. Depending on the configured workflow, this may consume credits, call external connectors, process sensitive records, or cause downstream side effects. The instruction does not require explicit user confirmation immediately before creation, does not show a dry-run or execution preview, and does not establish a maximum number of records. This is a least-privilege and authorization-boundary issue: an Agent selected for a read-oriented analytics task is instructed to use an authenticated capability that can modify workspace state. The audit found no evidence that the command elevates operating-system privileges or bypasses Cargo's native access controls; it instead exercises existing write privileges beyond the Skill's declared task boundary. ### Attack Path 1. A user asks the analytics Skill to inspect failed runs or retrieve failure statistics. 2. The Skill downloads failed-run information and extracts record identifiers. 3. The Agent follows the documented recovery sequence after a diagnosis or attempted fix. 4. Without a separate, explicit aut ...[truncated 1148 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases like 'give me the file' and 'download the results', which are generic enough to match ordinary conversation and cause unintended skill invocation. In an agent environment, overbroad routing can expose run outputs, exports, or signed download URLs in contexts where the user did not intend to invoke this specific data-retrieval capability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to run npx @cargo-ai/cli without a pinned version, which allows whatever package version is current at execution time to be fetched and executed. In a security-sensitive agent/tooling context, this creates a supply-chain risk: a compromised latest release, typo-squatted dependency resolution path, or breaking behavior change could alter what code runs on the user's machine.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This analytics/export skill includes a write operation (cargo-ai orchestration batch create) to re-run failed records, which exceeds its stated read-oriented scope. Scope drift is dangerous because an agent selecting this skill for low-risk retrieval tasks could be induced to perform state-changing actions, increasing the chance of unintended executions, cost incurrence, or data processing without appropriate user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The examples encourage bulk export of segment and run data, including records filtered on fields like email, without any warning about sensitive data handling, least-privilege use, or downstream storage risks. In a data-export skill, this omission increases the chance that users will broadly extract personal or operational data into insecure local files, shared terminals, or ad hoc analysis workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says this skill should handle run outputs, exports, and run/batch success and error counts, and explicitly says billing/credits questions should use cargo-billing. This example file nevertheless teaches a 'Per-workflow cost analysis' flow using cargo-ai billing usage get-metrics, expanding the skill into billing analytics beyond its declared purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest documentation says to skip requests about credits, plans, or invoices and use cargo-billing instead. In contrast, this reference section presents billing usage metrics as a supported 'full flow' within cargo-analytics, which actively conflicts with the stated skill boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation instructs users to download error runs for inspection without warning that run outputs may contain sensitive payload data, identifiers, prompts, or downstream system content. In an analytics/debugging context, this increases the chance of unnecessary data exposure, especially when broad time filters are used and outputs are retrieved outside least-privilege review paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file documents batch download and run download as returning signed URLs to exported files, but does not warn that these URLs grant access to potentially sensitive operational data. For markdown files, omission of privacy or data-handling warnings around export/access mechanisms can qualify as a missing user warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents run download-outputs returning per-run metadata plus input and output, which may contain user or system data, but it provides no warning about privacy, sensitivity, or careful handling of exported data. Under SQP-2 for markdown files, descriptions of behaviors that can affect user data should include a warning when exports may expose potentially sensitive content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The troubleshooting guide recommends running npx @cargo-ai/cli, which fetches and executes the latest package version at runtime rather than a pinned, reviewed version. In an agent skill context, this increases supply-chain risk: if the package or one of its dependencies is compromised, users following the guidance may execute attacker-controlled code.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The skill claims to focus on getting data out of Cargo and measuring run outcomes, but the discovery section includes listing plays, tools, workflows, agents, connectors, and models. Some discovery is needed to obtain UUIDs, but listing agents and connectors is broader administrative enumeration not clearly justified by the narrow analytics/export description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Earlier documentation explicitly directs billing, usage metrics, and subscription questions to the cargo-billing skill. The help section then presents cargo-ai billing usage get-metrics --help as an example command within this skill, which contradicts the stated boundary about when to use this skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.