Back to skill

Security audit

peter-code-review

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent pre-commit code review skill that runs normal local quality checks, with a notable caution around its unpinned TypeScript command.

Install only if you are comfortable with the agent running local repository validation commands. For Node/TypeScript projects, prefer changing the guidance to use a pinned project script or local `./node_modules/.bin/tsc` instead of allowing `npx` to download or resolve tooling dynamically.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Unpinned npx Invocation May Execute an Untrusted Registry Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:43
Vulnerability Type: Insecure dependency resolution and implicit package execution
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- Node/TS:
  - 必跑:`npm run lint`、`npx tsc --noEmit`

Technical Analysis

The skill instructs the agent to execute npx tsc --noEmit. If the reviewed repository does not provide a local tsc executable, npx may resolve and download a package from the configured npm registry. The command identifies the executable by the ambiguous package name tsc instead of requiring a lockfile-pinned installation of the official typescript package.

This creates a supply-chain risk because execution can depend on mutable registry content rather than dependencies already reviewed and installed from the repository lockfile. Package lifecycle scripts or the resolved executable can run arbitrary code with the privileges of the user operating the agent.

Attack Path

  1. An attacker prepares or influences a Node.js repository that lacks a local, lockfile-pinned TypeScript compiler.
  2. The user invokes this code-review skill against that repository.
  3. Following SKILL.md, the agent runs npx tsc --noEmit.
  4. Because no trusted local tsc executable is available, npx resolves the package through the configured npm registry and may download it.
  5. Registry-supplied package code or lifecycle scripts execute on the audit host under the agent user's account.
  6. The package can access files, environment variables, network resources, and credentials available to that account.

Exploitation depends on the local npm/npx version and configuration permitting package downloads, and on the absence of a trusted local executable.

Impact Assessment

Successful exploitation permits arbitrary code execution with the privileges of the user running the skill. The affected scope can include the reviewed repository, other files wr ...[truncated 275 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require typescript to be declared in the repository's development dependencies and pinned through a committed lockfile.

  2. Prohibit implicit package downloads during review.

  3. Invoke only the installed local executable, for example:

    bash
    ./node_modules/.bin/tsc --noEmit
    

    Alternatively, use an npm execution mode configured to reject installation when the executable is absent, such as:

    bash
    npm exec --offline --no -- tsc --noEmit
    
  4. Before execution, verify that the resolved binary belongs to the installed, expected typescript package.

  5. If the trusted local compiler is unavailable, record the type check as not executed instead of retrieving a package dynamically.

  6. Run repository-controlled validation commands in an isolated, least-privileged environment without production credentials.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill's behavior/output expectations in that locale without offering a language choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly justified, which is not documented here.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs execution of npx tsc --noEmit, which may resolve and run tooling from the environment without an explicitly pinned version. In a pre-commit review skill that encourages command execution in developer repositories, this creates supply-chain and reproducibility risk because different environments may fetch or use unexpected TypeScript versions, and in some cases npx can trigger package retrieval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing description and default prompt require Chinese output such as '提交前质量闸门' and classification as '可提交(高风险)' without offering a language choice or documenting a justified locale restriction. This is a natural-language policy concern because the skill appears to enforce a specific language for user interaction by default.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes when to run the skill using broad procedural language ('run pre-commit-review on review-workspace (or review-head when empty)') but does not clearly define activation scope, exclusions, or negative examples. In a manifest file, this can make invocation conditions ambiguous because it is unclear whether the skill should trigger automatically from any commit-related context or only via the named command.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.