Back to skill

Security audit

Likec4 Dsl

Security checks for vulnerabilities and agentic risk

Overview

This skill is a LikeC4 DSL and CLI reference package with some normal command-execution and supply-chain cautions, but no hidden, destructive, or deceptive behavior found.

Installers should prefer a local, reviewed LikeC4 dependency or an exact pinned command such as `likec4@1.53.0`, and should use LeanIX `--apply` only when they intentionally want to change LeanIX data with a valid token.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:114
Finding

Unpinned Remote npm Package Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:114-127
Vulnerability Type: Unsafe third-party package retrieval and immediate execution
Risk Level: Medium

Vulnerable Code Snippet

bash
npx likec4 validate --json --no-layout --file <edited-file> <project-dir>
bunx likec4 validate --json --no-layout --file <edited-file> <project-dir>
pnpm dlx likec4 validate --json --no-layout --file <edited-file> <project-dir>

Related guidance:

text
For evals/gradings/executions, be runner-tolerant
(npx/bunx/pnpm dlx), and judge correctness by subcommand
+ flags + project scope.

If workspace already has likec4 as a dependency, check its
version from package.json and ensure it is at least 1.53.0.
If pinning is needed, use the active runner
(npx/bunx/pnpm dlx) with likec4@1.53.0.

The same unsafe fallback pattern also appears in references/cli.md:3-8:

text
Examples use bunx to run the CLI, but you should use workspace's
package manager (e.g. bun, pnpm, npm).
If workspace is not a npm project, use bunx (if available) ->
pnpx (if available) -> npx as a fallback.

If workspace already has likec4 as a dependency, check its version
from package.json, make sure it is at least 1.53.0. Pin the version
bunx likec4@1.53.0 ... otherwise.

Technical Analysis

Package launchers such as npx, bunx, and pnpm dlx may resolve a package from a remote registry, download it, and immediately execute its command-line entry point. The primary examples use the unpinned package name likec4, so the effective code can change after this Skill has been reviewed.

Although the documentation mentions version 1.53.0, exact pinning is conditional rather than mandatory. It also does not require an integrity-checked lockfile, an approved registry, or prior installation of an audited local dependency. The downloaded package and its transitive dependency graph are absent from this repository and therefore were outside the ...[truncated 1631 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add LikeC4 as an exact-version workspace dependency and commit the package-manager lockfile.
  2. Invoke the audited local binary rather than permitting automatic registry fallback, for example through a package script or the package manager’s local-execution mode.
  3. Require deterministic installation with lockfile enforcement, such as npm ci, pnpm install --frozen-lockfile, or the equivalent for the selected package manager.
  4. If one-shot execution is unavoidable, require an exact reviewed version such as likec4@1.53.0; do not use an unversioned package name or @latest.
  5. Pin and review transitive dependencies through the lockfile, and use registry integrity metadata where supported.
  6. Restrict package resolution to an approved registry or internal mirror.
  7. Run the CLI in a sandbox with minimum filesystem access, a sanitized environment, and network access disabled unless the requested operation genuinely requires it.
  8. Update all examples in SKILL.md and references/cli.md so secure local, pinned execution is the default rather than optional guidance.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 391)May include surrounding context.

md
Load a reference file when the task involves the corresponding topic. Claude reads SKILL.md first; these files are loaded on demand only when needed.

| File                                         | Purpose — load when...                                                                                   |
| -------------------------------------------- | -------------------------------------------------------------------------------------------------------- |
| `references/specification.md`                | Writing/editing `specification { }` blocks, defining element/deploymentNode/relationship/tag/color kinds |
| `references/model.md`                        | Writing/editing `model { }` blocks, element hierarchy, relationships, `extend` patterns, property names  |

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.