Back to skill

Security audit

Social Copy Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward social media copywriting skill with disclosed HTML clipboard output, but users should be cautious about the unpinned npx install command in the README.

Install from a trusted, reviewed source and prefer pinned or verified install commands when available. The generated HTML includes copy buttons that write visible card text to the clipboard when clicked; review the produced copy before posting it publicly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:8
Finding

Unpinned npx Package Execution Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: README.md, line 8
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

bash
npx skills add dongsheng123132/social-copy-generator

Technical Analysis

The documented installation command invokes npx without specifying an exact version of the skills package. As a result, installation may resolve and execute a package release that differs from the version originally reviewed. The Skill source is also identified by a mutable GitHub owner/repository reference rather than an immutable commit hash.

This creates a time-of-check/time-of-use supply-chain risk: compromise of the npm package, its maintainer account, the referenced GitHub account, or the upstream repository could alter the code ultimately executed or installed. The repository itself contains no confirmed malicious executable code; the risk arises from the mutable external dependencies used by the installation procedure.

Attack Path

  1. An attacker compromises the npm package, a relevant maintainer account, or the referenced GitHub repository.
  2. The attacker publishes a malicious skills package release or replaces the repository content with a malicious Skill revision.
  3. A user follows the documented npx skills add dongsheng123132/social-copy-generator instruction.
  4. npx resolves and executes the unpinned package, which then retrieves or installs content from the mutable repository reference.
  5. Malicious installer logic may execute with the privileges of the user running the command.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. The resulting scope may include access to files, environment variables, credentials, and network resources available to that user. It could also allow modification of installed Skill content or other user-writable resources. The command does no ...[truncated 123 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the skills CLI to an exact, audited package version rather than relying on the current registry release.
  • Pin the Skill source to an immutable Git commit hash or signed release tag.
  • Use package-lock integrity data, checksums, or signature verification where supported.
  • Document the expected package publisher and repository ownership so users can verify provenance before installation.
  • Prefer an installation workflow that downloads and verifies artifacts before executing any installer code.
  • Periodically review pinned dependencies and update them through a controlled security-review process.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template sets <html lang="zh">, which imposes a specific locale in the generated output. The README does not state that output language is optional, user-selected, or justified as a region-specific tool, so this can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example prompts include generic requests like "Generate social media posts for my new project" and "Create launch posts for all platforms," which could match many ordinary user requests beyond this skill's intended scope. The README does not provide exclusion conditions or tighter trigger constraints to distinguish when this specific skill should activate versus other writing or marketing skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The listed use cases describe common intents like promoting a product or generating marketing content, but they do not clearly distinguish when this skill should activate versus when a more general writing or marketing skill should. The absence of constraints or negative examples makes the trigger scope ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template hard-codes <html lang="zh">, which imposes a Chinese locale regardless of whether the generated content is English or bilingual. This conflicts with the stated support for both Chinese and English and does not provide user opt-in or locale selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation examples include broad requests such as "Generate social media posts for my new project" and "Create launch posts for all platforms" without any narrowing context or exclusion conditions. In a skill-dispatch system, these phrases could collide with ordinary user requests and unintentionally trigger this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown describes that the skill outputs an HTML page, and the template includes one-click copy behavior via navigator.clipboard. However, there is no explicit user-facing warning that the result is an executable HTML artifact intended to be opened in a browser and used for clipboard operations, which could affect user expectations about local file handling and browser behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.