Back to skill

Security audit

Build Protocol Engineering

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent engineering workflow, but its audit script can run unpinned npx code in a user's project, which creates a review-worthy supply-chain execution risk.

Review before installing or using this skill. The workflow itself is reasonable, but run the audit script only in a sandboxed project checkout with minimal environment variables, and prefer changing the npx TypeScript check to a pinned local compiler or local-only npx mode before trusting it in sensitive repositories.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/audit-script-engineering.sh:266
Finding

Unpinned npx Execution May Retrieve and Run an Untrusted Package

Content
View full analysis

Vulnerability Details

File Location: references/audit-script-engineering.sh, lines 266-267
Vulnerability Type: Supply-chain risk from implicit remote package resolution and execution
Risk Level: Medium

Vulnerable Code

bash
if command -v npx &>/dev/null && [ -f "tsconfig.json" ]; then
  TS_ERRORS=$(npx tsc --noEmit 2>&1 | grep -c "error TS" || echo "0")

Technical Analysis

The audit script invokes npx tsc without requiring a lockfile-installed local TypeScript compiler, preventing package installation, pinning a version, or enforcing offline resolution.

Depending on the installed npm/npx version and project state, if the expected executable is unavailable locally, npx may resolve and download a package from the configured package registry and execute its binary. This allows the effective code run by the audited Skill to differ from the code reviewed in the Skill package.

The command is especially sensitive because the script is intended to run inside arbitrary software repositories. Any remotely resolved package executes with the invoking user's permissions and can access files and environment variables available to the audit process. Local TypeScript compilation is legitimate for the declared consistency-checking function, but allowing implicit network retrieval is not the minimum privilege necessary to perform it.

No direct secret transmission command was found. The script's fetch(...) pattern is only a source-code search, and its secret checks print findings locally. The security concern is the conditional supply-chain execution channel created by npx.

Attack Path

  1. A user runs the mandated audit script against a project containing tsconfig.json.
  2. npx is available, satisfying the condition on line 266.
  3. The intended TypeScript compiler executable is absent from the project's installed dependencies, or package resolution is influenced by an unsafe registry configuration.
  4. `n ...[truncated 1040 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require TypeScript to be installed as a pinned development dependency and committed to the project's lockfile.
  2. Invoke the verified local binary directly:
bash
if [ -x "./node_modules/.bin/tsc" ] && [ -f "tsconfig.json" ]; then
  TS_ERRORS=$(./node_modules/.bin/tsc --noEmit 2>&1 | grep -c "error TS" || echo "0")
else
  log_warn "Pinned local TypeScript compiler unavailable — skipping compilation check"
fi
  1. If npx must be retained, prohibit installation and require local resolution using an option supported by the project's pinned npm version, such as:
bash
npx --no-install tsc --noEmit
  1. Alternatively, use an explicitly offline package-execution mode and treat resolution failure as a skipped check or controlled blocker rather than permitting a download.
  2. Verify lockfile integrity in CI and use an approved registry with dependency allowlisting and package-integrity checks.
  3. Run the audit in a sandbox with network access disabled, minimal environment variables, read-only repository access where practical, and no production credentials.
  4. Document that the audit script performs no dependency installation and must not retrieve executable code during an audit.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/audit-script-engineering.sh (reported line 206)May include surrounding context.

sh
SECRET_PATTERNS=(
  "AKIA[0-9A-Z]{16}"          # AWS Access Key ID
  "sk-[a-zA-Z0-9]{32,}"       # OpenAI / Anthropic API key prefix
  "ghp_[a-zA-Z0-9]{36}"       # GitHub personal access token
  "ghs_[a-zA-Z0-9]{36}"       # GitHub Actions token
  "xox[baprs]-[0-9A-Za-z]"    # Slack token
  "-----BEGIN (RSA|EC|OPENSSH) PRIVATE KEY-----"  # Private keys

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill references executable artifacts and commands, including running a shell audit script and performing deployment-related actions, but it does not declare an explicit tool scope such as allowed tools or permissions. In an agent framework, that ambiguity can cause over-broad tool access at runtime, increasing the chance the agent uses shell, network, or environment access beyond what is necessary for a documentation/workflow skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/engineering-workflow.md (reported line 171)May include surrounding context.

md
Performance audit:
- [ ] N+1 queries (loop that calls DB per row)
- [ ] Missing indexes on common WHERE conditions
- [ ] Unbounded queries (no LIMIT clause)

Consistency audit (use script):
- [ ] Env var names consistent across all config files

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/engineering-workflow.md (reported line 194)May include surrounding context.

md
- [ ] Who to notify at each stage
- [ ] Estimated time per step

**Exit gate**: Runbook dry-run on staging. Another person reads the runbook and can execute it without asking questions.

---

Static analysis

No suspicious patterns detected.