Back to skill

Security audit

Algorithmic Art

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused p5.js generative-art helper with some disclosure and dependency caveats, but no evidence of credential access, persistence, destructive behavior, or hidden control.

Before installing, be aware that this skill creates executable HTML/JavaScript art viewers and relies on public CDN resources unless the generated output is modified to bundle or integrity-pin them. The Anthropic-styled template may also make outputs look more official than they are, so shared artifacts should be treated as user-generated content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
templates/viewer.html:21
Finding

Third-Party JavaScript Loaded Without Subresource Integrity

Content
View full analysis

Vulnerability Details

File Location: templates/viewer.html, line 21
Vulnerability Type: Unprotected third-party executable dependency
Risk Level: Medium

Complete Code Snippet:

html
<script src="https://cdnjs.cloudflare.com/ajax/libs/p5.js/1.7.0/p5.min.js"></script>

Technical Analysis

The HTML template loads executable p5.js code from a third-party CDN at runtime without a Subresource Integrity (integrity) attribute. Although the dependency is pinned to version 1.7.0 and retrieved over HTTPS from a reputable CDN, the browser does not verify that the response matches a cryptographically approved artifact.

Consequently, the code ultimately executed by artifacts generated from this template can differ from the code present during the static audit. A compromise affecting the CDN asset or its delivery could cause attacker-controlled JavaScript to execute in the artifact's browser context.

This external dependency also conflicts with the Skill's description of the resulting HTML artifact as completely self-contained.

Attack Path

  1. A user creates or receives an HTML artifact derived from templates/viewer.html.
  2. The user opens the artifact in a browser while connected to the network.
  3. The browser requests p5.min.js from cdnjs.
  4. An attacker who has compromised the hosted asset or its delivery supplies a modified response.
  5. Because no integrity hash is specified, the browser accepts and executes the modified JavaScript.
  6. The malicious script operates with the same browser-page privileges as the legitimate p5.js library.

Impact Assessment

Successful exploitation permits arbitrary JavaScript execution within the generated artifact's browser context. The malicious dependency could manipulate the interface and artwork, inspect data available to the page, capture user input entered into the artifact, initiate unauthorized network requests, or misrepresent downloaded outpu ...[truncated 228 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer bundling a reviewed copy of p5.js directly into the generated HTML so the artifact is genuinely self-contained and does not retrieve executable code at runtime.
  2. If CDN delivery must remain, calculate and specify the official cryptographic Subresource Integrity hash:
    html
    <script
      src="https://cdnjs.cloudflare.com/ajax/libs/p5.js/1.7.0/p5.min.js"
      integrity="sha384-REPLACE_WITH_VERIFIED_HASH"
      crossorigin="anonymous"></script>
    
  3. Obtain the hash from a trusted source or calculate it from a separately verified release artifact; do not copy an unverified hash from the same delivery channel.
  4. Retain exact-version pinning and review dependency updates before changing the pinned version or integrity hash.
  5. Apply a restrictive Content Security Policy that limits script execution and network destinations to explicitly approved sources.
  6. Consider self-hosting reviewed font resources as well to reduce third-party requests and avoid disclosing routine client metadata to external font providers.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation language is broad enough to match many ordinary requests about art, code, particles, or flow fields, which can cause the skill to trigger in contexts where the user did not specifically ask for this workflow. Over-broad invocation increases the chance that users are steered into this skill's more prescriptive instructions, including its branding/template constraints and HTML-generation behavior, without clear necessity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest frames the skill as creating original algorithmic art and specifically cautions against copying existing artists' work. However, the implementation instructions explicitly direct the agent to use templates/viewer.html as a literal starting point and keep the fixed sections exactly as shown, including branding, styling, and layout. That creates a mismatch between the claimed emphasis on originality and the prescribed reuse of a specific preexisting presentation layer.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Mandating preservation of Anthropic branding in all generated artifacts creates a trust and impersonation risk: users may reasonably infer the generated artifact is officially endorsed or reviewed by Anthropic even when it is not. In a skill that emits executable HTML/JS, forced branding can amplify social-engineering potential by making arbitrary generated code appear more authoritative and safe.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Requiring preservation of Anthropic branding without user choice or contextual need creates a misleading-authority risk similar to brand impersonation. Because the skill outputs self-contained HTML artifacts with interactive controls and inline JavaScript, the branding requirement can make generated content seem first-party or vetted, increasing the likelihood that users trust and run it without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.