Back to skill

Security audit

pixelmsg

Security checks for vulnerabilities and agentic risk

Overview

This image-card skill is mostly coherent, but it renders active HTML with unrestricted network access and mutable third-party scripts, so users should review it before installing.

Install only if you are comfortable with templates loading third-party CDN code during rendering. Avoid rendering sensitive, private, or attacker-supplied content until network access is blocked or resources are vendored locally, use unique workspace output filenames, and prefer keeping generated templates in a project workspace rather than modifying the installed skill directory.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
templates/shanghai-weather.html:6
Finding

Mutable Third-Party JavaScript Is Retrieved and Executed During Rendering

Content
View full analysis
``` The Skill instructions also explicitly prescribe this pattern: ```html ``` ### Technical Analysis The templates execute JavaScript retrieved from third-party CDNs whenever Playwright renders a card. The Tailwind URL is unversioned, while the Alpine URL uses the mutable `3.x.x` version range. Neither script has a Subresource Integrity hash. Consequently, the effective executable payload is not fixed to the package version that was audited. A CDN compromise, account compromise, DNS or network-layer redirection under a compromised trust chain, or malicious update to a mutable CDN alias could cause different JavaScript to execute during a later render. The downloaded scripts run in the rendered page and can read its DOM, including any information embedded in a generated card. They can also make outbound network requests because the renderer does not restrict br ...[truncated 1432 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
screenshot.mjs:93
Finding

Renderer Executes Arbitrary HTML Without Path or Network Restrictions

Content
View full analysis
[output-dir] [viewport]}" ``` ### Technical Analysis The command-line parser accepts any non-option value as the input HTML file. `resolve()` converts it to an absolute path but does not validate that the resolved path remains under the project's trusted `templates/` directory. Playwright loads the selected document with JavaScript enabled. No `page.route()` handler blocks external requests, no Content Security Policy is injected, and no validation rejects active elements such as remote scripts, iframes, or scripted network calls. Rendering arbitrary HTML is part of the tool's intended flexibility, but it creates a security boundary that is not documented or enforced. If an attacker can influence a template's content or convince an agent to render an attacker-controlled HTML file, the attacker gains JavaScript execution in the Chromium page context and outbound browser-network access. The supplied `sh ...[truncated 1907 chars]
Remediation
View remediation
{ const requestURL = new URL(route.request().url()); if (requestURL.protocol === "file:") { await route.continue(); } else { await route.abort(); } }); ``` 4. Vendor all required scripts, styles, and fonts locally so normal rendering does not require network access. 5. Disable JavaScript when rendering static cards. Where JavaScript is required, use reviewed local code and inject a restrictive Content Security Policy. 6. Treat user-provided HTML as untrusted and render it in an isolated worker or container with limited network access, filesystem exposure, memory, CPU, and execution time. 7. Document the renderer's trust boundary and require explicit confirmation before rendering templates received from untrusted users. 8. Enforce navigation, request, and timeout limits and close the browser through `try/finally` cleanup on failures. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (38)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill encourages use whenever an image might be more polished than text and says to prefer generating an image when in doubt. Over-broad invocation increases unnecessary execution of rendering tooling, file creation, and browser-based processing, which enlarges exposure to downstream risks from untrusted content and side effects.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
internally by `screenshot.mjs`) and prints a single line: the **absolute

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
internally by `screenshot.mjs`) and prints a single line: the **absolute

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
internally by `screenshot.mjs`) and prints a single line: the **absolute

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The plan explicitly instructs modification of SKILL.md, which is self-modification of the agent skill definition. Allowing a skill to rewrite its own instructions is dangerous because it can alter future behavior, permissions, or safety boundaries in ways that persist beyond the original task.

Content

Scanner excerpt · docs/plans/2026-04-06-github-publish.md (reported line 348)May include surrounding context.

md
---

### Task 8: Regenerate English screenshots and update SKILL.md

After all template changes, regenerate the canonical English screenshots:

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The explicit git add/commit of SKILL.md turns the self-modification into a persisted repository change, increasing the risk that altered behavior is stored and propagated. In an automated environment, this can permanently weaken safeguards or change invocation semantics without adequate review.

Content

Scanner excerpt · docs/plans/2026-04-06-github-publish.md (reported line 365)May include surrounding context.

bash
git add SKILL.md
git commit -m "docs: update SKILL.md render.sh viewport documentation"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes templates that use Tailwind and Alpine via CDN but does not warn that rendering these templates causes Playwright to fetch and execute third-party remote resources. In an agent skill that automatically renders user-facing content, this increases supply-chain and privacy risk because external scripts can change over time, fail unpredictably, or observe request metadata from the rendering environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README tells template authors to avoid external API calls at render time, yet explicitly documents a live Shanghai weather template that fetches external data during rendering. In this skill context, rendering occurs in a browser automation environment, so network-loaded content can leak metadata, create nondeterministic output, and expand the trust boundary to third-party services.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx playwright install chromium without pinning a specific package version. npx may resolve and execute the latest package from the registry, so a malicious or compromised upstream release could run arbitrary code on the user's machine during installation. In this context, the risk is real because this skill relies on Playwright as part of setup, making copy-paste execution by users likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README recommends npx skills add pixelmsg without pinning the skills package version. This causes npx to fetch and execute whatever version is current at the time, which creates a supply-chain execution risk if the package is hijacked, typosquatted, or publishes a malicious update. The skill context increases exposure because installation instructions are aimed at agent users who may execute commands verbatim.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The 'When to Use' guidance is open-ended and lacks limiting conditions, making accidental or excessive invocation likely. In security terms this is risky because it promotes unnecessary use of a toolchain that writes files and renders HTML, but the section itself does not directly enable code execution or data exfiltration.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The instruction to place newly written templates into the skill's templates/ directory encourages persistent modification of skill assets rather than ephemeral workspace use. Persistent writes can accumulate unreviewed HTML/JS artifacts, create cross-session contamination, and make later executions consume attacker-influenced or stale content.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
**Use an existing template when:** the content type maps directly (weather → weather.html, trending repos → github-trending.html).

**Write a new template when:** the content type is unique, or the required data doesn't fit cleanly into an existing template's structure. New templates go in `templates/` and follow the Design System below.

---

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation says rendering should avoid external API calls, but the example template fetches Tailwind, Alpine.js, and fonts from remote CDNs at render time. This creates network dependency, leaks execution metadata to third parties, and expands the supply-chain attack surface because unpinned remote resources execute in the renderer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The sample HTML sets <html lang="zh">, which imposes a specific locale in the template guidance. Because the skill is presented as general-purpose and does not state that it is China-specific or user-selected, this can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs copying output into a workspace path using a fixed filename pattern without warning about overwriting existing files or validating destination safety. This can cause unintended file replacement, persistence of generated artifacts, and operational issues on platforms where the workspace is shared or later exposed back to users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This plan directs deletion of files and git commit operations that are not necessary to the skill's narrow runtime purpose of rendering HTML to image cards. In an agent setting, embedding repository-maintenance actions inside a skill plan increases the chance that the agent performs unauthorized or user-unexpected modifications to the local workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented rm command irreversibly deletes multiple files and is presented as a routine implementation step without any safety warning, backup guidance, or confirmation requirement. In an agentic environment, such destructive instructions can lead to unintended data loss if executed automatically or in the wrong repository state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The plan includes broad repo changes such as creating .gitignore, LICENSE, and rewriting package.json, which exceed the stated rendering/messaging behavior of the skill. Overbroad instructions like this can cause an autonomous agent to make supply-chain, packaging, or documentation changes without clear authorization, expanding the blast radius well beyond image generation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a skill for rendering HTML templates to PNG cards and sending them as rich image messages in response to user requests. This file instead implements a standalone command-line screenshot utility that renders local HTML files to PNGs on disk, with no messaging or delivery functionality at all. That is a meaningful behavior gap, not just an implementation detail.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template pulls executable JavaScript (Alpine.js) and fonts from third-party CDNs during rendering. In an HTML-to-PNG pipeline using Playwright, this creates avoidable network dependency and exposes rendering to supply-chain compromise, tracking, unexpected script behavior, or SSRF-like outbound requests in environments that should ideally be offline and deterministic.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template loads remote fonts and third-party JavaScript from Google Fonts, Tailwind CDN, and jsDelivr/AlpineJS, which causes code and assets outside the repository to execute or influence rendering. For an image-rendering skill, this materially expands the trust boundary and creates supply-chain and privacy risk, since a compromised CDN or changed upstream asset can alter behavior, exfiltrate data, or break reproducibility.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The explicit transmission to api.open-meteo.com creates outbound network activity from the rendering environment to a third party. Even though the payload here is only fixed coordinates, in this skill context any template-level outbound request is risky because similar patterns could be repurposed to send sensitive rendering-time data or permit remote influence over generated output.

Content

Scanner excerpt · templates/shanghai-weather.html (reported line 68)May include surrounding context.

html
}
}" x-init="
  try {
    data = await (await fetch('https://api.open-meteo.com/v1/forecast?latitude=31.23&longitude=121.47&current=temperature_2m,relative_humidity_2m,apparent_temperature,weather_code,wind_speed_10m,wind_direction_10m&daily=weather_code,temperature_2m_max,temperature_2m_min&timezone=Asia/Shanghai&forecast_days=5')).json()
  } catch(e) {
    data = {
      current: { temperature_2m: 22, apparent_temperature: 20, relative_humidity_2m: 68, weather_code: 2, wind_speed_10m: 12, wind_direction_10m: 135 },

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template performs a live fetch to an external weather API during rendering, so the renderer is no longer just presenting provided content; it is executing network-active behavior. In a Playwright-based rendering skill, this can leak environment metadata such as IP address, enable nondeterministic output, and create a path for unreviewed external dependencies to influence rendered content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.