T08 · Insecure Dependencies
- Location
SKILL.md:52- Finding
Unpinned Third-Party Package Download and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its local AI-usage analytics purpose, but it needs review because it can download and run an unpinned PyPI CLI while reading broad local agent-history metadata.
Install only if you are comfortable with a tool scanning local AI-agent usage metadata such as projects, models, tokens, and usage patterns. Prefer using a preinstalled or pinned, reviewed `agentype-cli` version instead of allowing the unpinned `uvx` fallback to fetch and execute the latest package at runtime.
SKILL.md:52Unpinned Third-Party Package Download and Execution
The skill directs collection of local AI-agent history, token metadata, top projects, models, and usage rhythm, but it does not require an explicit user-facing privacy warning or consent check before reading that data. Even if the intent is analytics, these sources can reveal sensitive project names, work patterns, model usage, and other behavioral metadata, creating privacy risk especially in shared or enterprise environments. The context makes this more dangerous because the whole purpose of the skill is to aggregate local usage data across multiple agent ecosystems.
The skill instructs use of uvx --from agentype-cli agentype --json-out without pinning an exact package version. That allows the executed code to vary over time and creates a supply-chain risk where a malicious or compromised upstream release could run arbitrary code on the local machine when the skill is invoked. Because this skill is explicitly meant to inspect local agent history, it would likely run with access to sensitive local metadata, increasing the consequence of a bad package update.
No suspicious patterns detected.