Back to skill

Security audit

cargo-context

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing a Cargo context repository, but it grants broad write and sandbox command authority through an unpinned CLI package.

Review before installing. Use a pinned, reviewed @cargo-ai/cli version, confirm the active workspace before any write/edit, avoid broad automatic invocations, and treat runtime execute as a privileged sandbox command rather than a safe read-only helper.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned npm CLI Dependency Allows Supply-Chain Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–16 and line 44
Vulnerability Type: Unpinned third-party npm dependency
Risk Level: Medium

Vulnerable Code

yaml
install:
  - kind: node
    package: "@cargo-ai/cli@latest"
    bins:
      - cargo-ai
bash
npm install -g @cargo-ai/cli            # no global install? prefix every command with `npx @cargo-ai/cli`

Technical Analysis

The Skill installs @cargo-ai/cli@latest and recommends an unversioned npx @cargo-ai/cli fallback. Both mechanisms resolve package contents dynamically at execution time rather than binding the Skill to a reviewed, immutable release.

Consequently, the code that executes when the Skill is installed or invoked can differ from the code available during this audit. If the npm package, maintainer account, release pipeline, or registry distribution path is compromised, a malicious release can execute package lifecycle scripts or malicious CLI behavior with the invoking user's permissions.

The global installation recommendation increases the potential scope because it modifies the user's global Node.js environment. The Skill later uses the CLI to access Cargo authentication state, workspace content, uploaded files, external integrations, and Git-backed repositories, so a compromised CLI could potentially act within those accessible privileges.

Attack Path

  1. An attacker compromises the npm publishing credentials, release pipeline, maintainer account, or another part of the distribution path for @cargo-ai/cli.
  2. The attacker publishes a malicious release that becomes the package's latest version.
  3. A user installs the Skill, runs npm install -g @cargo-ai/cli, or invokes the documented unversioned npx @cargo-ai/cli fallback.
  4. npm downloads the malicious version and may execute package-controlled installation or CLI code.
  5. The malicious code runs with the invoking user's operating-system permissions.
  6. It may access files, e ...[truncated 1003 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @cargo-ai/cli@latest with an exact, reviewed version:

    yaml
    install:
      - kind: node
        package: "@cargo-ai/cli@1.2.3"
        bins:
          - cargo-ai
    
  2. Pin the documented installation and fallback commands to the same version:

    bash
    npm install -g @cargo-ai/cli@1.2.3
    npx --yes @cargo-ai/cli@1.2.3
    
  3. Validate package provenance, publisher identity, release signatures where supported, and registry integrity before approving upgrades.

  4. Use a lockfile and integrity metadata where the installation environment supports them.

  5. Establish a controlled dependency-update process in which each new version is reviewed and tested before changing the pin.

  6. Prefer a project-local installation over a global installation where practical, reducing modifications to the user's global Node.js environment.

  7. Run the CLI under a least-privileged operating-system account and use workspace-scoped Cargo tokens with only the permissions required for the task.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents a command that runs arbitrary shell commands in the runtime sandbox, which materially expands capability beyond the stated purpose of managing a markdown knowledge base and graph. Even if framed as inspection-only, unrestricted command execution can be abused to enumerate files, access secrets present in the sandbox, stage unintended modifications, or invoke network/system utilities depending on environment controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad natural-language requests such as 'update our context', 'what is in the context repo', and 'who do we sell to', which can overlap with ordinary conversation and cause unintended skill activation. In this skill, unintended activation is more dangerous because the skill can perform immediate write/edit operations that push to the default branch of a git-backed repository.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill instructs use of npx @cargo-ai/cli and also installs @cargo-ai/cli@latest, which allows execution of an unpinned package version at runtime. If the upstream package is compromised or a breaking/malicious release is published, users may execute unexpected code with access to workspace credentials and context-repo write capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The rename/delete guidance tells users to remove files via GitHub UI or execute-assisted workflows without emphasizing deletion consequences, recovery expectations, or the need to verify references before removal. In a git-backed knowledge repository, deleting the wrong file can silently break graph links, lose contextual history for consumers, and disrupt downstream workflows that rely on stable slugs or referenced documents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly instructs use of cargo-ai context runtime execute to run grep, introducing a general command-execution capability into a skill whose stated purpose is maintaining a markdown knowledge base. Even though the example uses a harmless command, normalizing execute broadens the operational scope and can lead agents or users to run other shell commands against the runtime, increasing the risk of unintended file access, modification, or misuse of the sandbox.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest scopes this skill to reading and writing the GTM knowledge base, its runtime sandbox, and typed knowledge graph. The fallback guidance to create a workspace-management report uses a separate operational capability for ticketing/reporting, which is not necessary to author or inspect context content and is not declared in the skill description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation claims runtime execute should be used only for inspection, but the described interface accepts an arbitrary command plus argument array and therefore does not enforce that limitation. This mismatch can mislead downstream agents or users into trusting a dangerous primitive as safe, increasing the chance of policy bypass or unsafe automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.