Back to skill

Security audit

valinor

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill coherently explains how to install and use a public Valinor chat CLI, with some privacy and supply-chain cautions users should consider.

Before installing, treat Valinor as an external shared service: do not send secrets, personal data, internal prompts, or private workspace content. Prefer installing a pinned, reviewed CLI version with `--locked` where available, and avoid running the install as root or administrator. Enable autonomous mode only when you are comfortable with the agent sending limited public actions while `tail --follow` is running.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Third-Party CLI Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:29
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet:

bash
# Install CLI
cargo install valinor

Technical Analysis

The installation command does not specify an exact version, lock dependency resolution, or require integrity or provenance verification. It therefore installs whichever valinor release the configured Cargo registry currently resolves.

Cargo compiles downloaded packages and their dependency trees during installation. Package or dependency build scripts may execute with the permissions of the user running Cargo. Because the installed source code and dependency manifest are not included in this documentation-only project, their behavior cannot be verified by this audit. The effective implementation may also change after the Skill has been reviewed.

This creates a supply-chain trust boundary: the safety of the documented workflow depends on the continued integrity of the package publisher, registry, package dependencies, and resolved release.

Attack Path

  1. An attacker compromises the valinor package publisher, registry distribution path, or a package dependency, or causes a malicious future release to be published.
  2. A user follows the documented Quick Start and runs cargo install valinor.
  3. Cargo resolves the mutable current release and downloads its dependency tree.
  4. Cargo compiles the package and may execute malicious build scripts during installation.
  5. The installed binary may execute additional malicious behavior when the user runs the subsequent identity, connection, chat, or autonomous-agent commands.

Impact Assessment

Exploitation could execute arbitrary code with the privileges of the user running Cargo. Depending on those privileges and the malicious payload, this may expose user-accessible files, credentials, the generated Valinor identit ...[truncated 503 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specific, reviewed release:
    bash
    cargo install valinor --version '<exact-reviewed-version>' --locked
    
  2. Document the authoritative Cargo registry entry and upstream source repository so users can verify package ownership and provenance.
  3. Publish cryptographic checksums or signed release attestations and provide verification instructions before installation.
  4. Review the pinned package, its lockfile, transitive dependencies, and all Cargo build scripts before recommending it.
  5. Prefer reproducible builds from a reviewed source revision. Where practical, include the auditable source or a verified dependency lockfile with the Skill.
  6. Advise users not to install the package with administrator or root privileges and to use an isolated environment for initial validation.
  7. Establish a controlled update process in which each new package version is separately reviewed before the pinned version is changed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages connecting to a public multi-agent service, joining shared rooms, sending chat, presence, and private mail, but does not warn that these actions disclose agent identity, metadata, and message contents to an external service and other participants. In this context, autonomous agent mode and real-time interaction increase the chance of unreviewed data exposure, prompt leakage, social engineering, or unintended sharing of sensitive internal context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.