Back to skill

Security audit

前端性能审计清单

Security checks for vulnerabilities and agentic risk

Overview

This skill is a front-end performance checklist with one disclosed optional Lighthouse command, and I found no hidden persistence, credential access, or destructive behavior.

Before installing, note that the skill is written in Chinese and includes an optional Lighthouse command. If you run the command in a sensitive project, prefer a pinned Lighthouse version or a locally locked dependency workflow instead of resolving the latest package with `npx`.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 30
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code:

bash
npx lighthouse https://your-site.com --output html --output-path ./report.html

Technical Analysis

The documented command invokes lighthouse through npx without specifying an approved package version. If the package is not already available locally, npx may retrieve and execute a mutable release from the configured package registry. The command also provides no lockfile or integrity verification.

Consequently, the code executed when users follow this instruction can differ from the code originally reviewed. Exploitation would require compromise of the upstream package, registry, dependency chain, or package-resolution environment. No evidence in the audited files indicates that the skill author controls such a payload or intentionally introduced a malicious package.

Attack Path

  1. A user follows the command documented in SKILL.md.
  2. npx resolves lighthouse through the user's configured package registry.
  3. If it is unavailable locally, npx downloads the currently resolved package and its dependencies.
  4. A compromised or unexpectedly changed package executes during installation or invocation.
  5. The package runs with the permissions and environment access of the user who launched npx.

Impact Assessment

A compromised dependency could execute arbitrary code with the invoking user's privileges. Depending on the user's environment, this could expose readable project files, environment variables, local credentials, and network-accessible resources, or modify files writable by that user. The audited project itself contains no embedded executable scripts, persistence mechanism, privilege-escalation logic, credential access, or data-exfiltration behavior.

Remediation
View remediation

Remediation Suggestions

  • Pin Lighthouse to a specifically reviewed version, for example:

    bash
    npx --yes lighthouse@12.8.2 https://your-site.com --output html --output-path ./report.html
    
  • Regularly review and deliberately update the pinned version rather than resolving an unspecified release.

  • For reproducible organizational workflows, declare Lighthouse in a development manifest, commit the lockfile, use deterministic installation such as npm ci, and invoke the locally installed binary.

  • Apply registry allowlisting, lockfile integrity validation, and dependency scanning where the command is used in sensitive environments.

  • Prefer the built-in Chrome DevTools Lighthouse workflow when local third-party package execution is unnecessary.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description and the entire skill content are written exclusively in Chinese, which imposes a specific language on users without any opt-in or alternative. Under the policy, locale or language constraints should either be user-selectable or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest includes a Chinese-only displayName ("前端性能审计清单") with no indication that the skill is region-specific or that users can opt into a language preference. This can violate language/locale policy expectations when a skill is presented to a broader audience without documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.