Back to skill

Security audit

skill-scaffolder 精简技能架构

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently scaffolds new Claude Code skills and discloses its file-writing behavior, with install and trigger-breadth caveats but no evidence of hidden execution, data theft, or destructive actions.

Before installing, prefer ClawHub or a reviewed pinned installer over the unpinned npx command. Use the skill only when you intend to create a new skill scaffold, give it a fresh target directory, and review generated files before enabling or publishing them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:66
Finding

Unpinned Third-Party Package Execution via npx

Content
View full analysis

Vulnerability Details

File Location: README.md, line 66
Vulnerability Type: Supply-chain risk caused by an unpinned executable dependency
Risk Level: Medium

Vulnerable Code:

bash
npx skills add David0Ming/skill-scaffolder

Technical Analysis

The documented installation command invokes the third-party skills npm package without specifying a version or integrity constraint. If the package is not already available locally, npx may retrieve its current published version and execute it with the installing user's privileges.

Because the package version is mutable from the perspective of this project, the code executed during installation may differ from the code reviewed when this skill was audited. Compromise of the npm publisher account, package, or transitive dependency chain could therefore turn this documented installation procedure into an arbitrary-code execution channel.

This finding concerns the installation instruction rather than embedded project code. The audited project itself contains only documentation and templates; no malicious scripts were found in the project directory.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or a transitive dependency used by the unpinned skills package.
  2. The attacker publishes a modified package version containing malicious installation or runtime behavior.
  3. A user follows the command documented at README.md:66.
  4. npx resolves and downloads the attacker-controlled package version.
  5. The package executes under the user's account during the installation workflow.
  6. The malicious package can perform actions permitted to that user before or while installing the skill.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running npx. Depending on that user's permissions and environment, an attacker could read or modify user-accessibl ...[truncated 430 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to a specific reviewed package version:
    bash
    npx --yes skills@<reviewed-version> add David0Ming/skill-scaffolder
    
  2. Verify the selected package version and its transitive dependencies before publishing the command.
  3. Use lockfiles and npm integrity metadata where the installation workflow supports them.
  4. Prefer an immutable, checksum-verified release artifact or a signed and reviewed source commit.
  5. Document the expected package publisher, exact version, checksum, and verification procedure.
  6. Recommend running installation with least privilege and without unnecessary credentials in the process environment.
  7. Periodically review the pinned version before upgrading rather than automatically resolving the latest release.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
- `SKILL.md`(core_rule only)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx skills add ... without pinning a specific package version. This can cause users to fetch and execute whatever version is current at install time, increasing supply-chain risk if the package is compromised or a breaking/malicious release is published. In the context of a skill installer, that risk is more significant because the command is explicitly meant to install code into a trusted local agent environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage examples include broad natural-language triggers such as asking to 'draft a new skill' or 'scaffold a skill that does X', which may match in situations broader than intended. For an agent skill that can create files and shape downstream behavior, unintended invocation could lead to accidental file generation, workflow disruption, or users receiving scaffolded content when they meant to ask for general advice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README says Claude will write the scaffold to the chosen path but does not prominently warn users that multiple files will be created on disk. For a file-writing skill, insufficient disclosure can cause accidental overwrites, unexpected repository changes, or writing into sensitive paths if the user misunderstands the behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description triggers on very common actions like drafting, designing, or creating a skill, which can cause this skill to activate for many unrelated requests. Over-broad routing increases unintended invocation risk, causing the agent to scaffold or rewrite artifacts when the user wanted general discussion, planning, or edits to an existing skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Trigger section uses ambiguous conditions such as '用户要求起草 / 设计 / scaffold / 新建一个 skill' and '用户有 idea 要落成 skill', which are broad enough to match normal ideation or documentation tasks. This can misroute agent behavior, leading to accidental file generation or application of the skill's workflow in contexts where it does not belong.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The when condition is broadly phrased and can trigger on vague requests like understanding paper basis or uncertainty about taxonomy boundaries, rather than a narrowly scoped scaffolding task. In a skill-selection system, this increases the chance of unintended activation, which can crowd out more appropriate skills or steer the agent into applying structural guidance in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L002 describes activation with broad natural-language conditions like '某步骤拿不准' and '想看完整前后走查', which can overlap with many general review or uncertainty situations. It does not define specific trigger phrases, scope boundaries, or negative examples, so the skill could be invoked in unintended contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill content, including activation metadata and instructional examples, is written exclusively in Chinese, implying a fixed language/locale for use. There is no indication that users may opt into another language or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level when condition is broad enough to match generic drafting or file-splitting tasks, which can cause the skill to be invoked outside its intended niche. In an agentic system, over-broad routing increases prompt-surface exposure and can steer the model into applying this scaffold workflow when a more specific or safer skill should handle the request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template explicitly recommends vague when phrasings like '想...', '不确定...', and '写...', which are semantically broad and likely to match many unrelated user intents. Because this file is a scaffolding template, it propagates the anti-pattern into future skills, amplifying unintended invocation risk across every skill generated from it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file includes a Chinese-language introduction inline, but does not explain whether the skill operates bilingually or how language choice is handled for users. Under the policy, locale-specific language behavior should be optional or explicitly documented rather than implied.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.