Back to skill

Security audit

技能查找

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for finding skills, but it recommends unpinned remote CLI commands and global auto-confirmed installs of third-party skills, which needs careful review before use.

Install only if you trust the Skills CLI and the specific skill source. Prefer browsing the catalog first, pinning CLI versions where possible, avoiding '-g -y' by default, reviewing the target repository and exact revision, and keeping installs local or reversible when testing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned Third-Party CLI and Unattended Global Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27–32 and 83–89
Vulnerability Type: Supply-chain exposure through unpinned dependencies and unsafe installation defaults
Risk Level: Medium

Vulnerable Code

markdown
- `npx skills find [query]` - Search for skills interactively or by keyword
- `npx skills add <package>` - Install a skill from GitHub or other sources
- `npx skills check` - Check for skill updates
- `npx skills update` - Update all installed skills
markdown
If the user wants to proceed, you can install the skill for them:

```bash
npx skills add <owner/repo@skill> -g -y

The -g flag installs globally (user-level) and -y skips confirmation prompts.

text

### Technical Analysis

The instructions invoke `npx skills` without pinning the CLI to an audited version. Depending on the local npm environment, `npx` may retrieve and execute the currently published package, meaning its implementation can change after this skill has been reviewed.

The skill also permits packages from GitHub or unspecified “other sources” and recommends installation using `-g -y`. Global installation expands the package's user-level scope, while `-y` suppresses interactive confirmation. The instructions do not require verification of repository ownership, immutable commit identifiers, package integrity hashes, signatures, or downloaded skill contents before installation.

This creates a supply-chain trust gap: a compromised package release, malicious repository, dependency-confusion event, typosquatted source, or manipulated search result could cause attacker-controlled components or instructions to be installed.

### Attack Path

1. A user asks the agent to locate a skill for a specialized task.
2. The agent invokes the unpinned `npx skills` CLI, potentially downloading and executing the currently published version.
3. The CLI or search service presents an attacker-controlled or compromised skill as a relevant result.
4. The user agre
...[truncated 1043 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a reviewed, explicit version, such as npx skills@&lt;approved-version&gt;, and verify package integrity through an approved lockfile, checksum, or signature mechanism.
  2. Restrict installations to an allowlist of trusted owners and repositories.
  3. Reference immutable commit hashes or signed release tags rather than mutable branches or unqualified package identifiers.
  4. Inspect the complete downloaded skill package, including scripts, hooks, dependencies, and instruction files, before installation.
  5. Avoid global installation by default. Prefer a project-local, isolated, or sandboxed installation with minimal filesystem, network, and credential access.
  6. Remove -y from the recommended command. Require explicit confirmation that displays the resolved source, version or commit, requested scope, and relevant installation behavior.
  7. Separate discovery from installation so search results are never installed automatically.
  8. Revalidate provenance and integrity before updates, and do not perform unrestricted bulk updates of installed skills.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are overly broad, covering generic phrases like 'how do I do X' and 'can you do X' that appear in many normal conversations. In an agent system, such broad routing can cause this skill to activate unnecessarily and steer users toward package discovery/installation flows, expanding exposure to the risky commands elsewhere in the skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning an exact package version, which causes execution of whatever package version is current at runtime. Because this skill is explicitly about discovering and installing third-party skills, an upstream compromise, malicious update, or typosquat in the package resolution path could lead to arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command reference invokes npx skills without a pinned version, so execution depends on the latest published package at the time the user runs it. In a package-manager context, that exposes users to supply-chain attacks and unexpected behavior changes, especially since the command is positioned as a normal workflow step.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill recommends npx skills add <package> without pinning the CLI version, meaning the bootstrap executable itself is mutable and fetched at execution time. That creates a direct supply-chain execution path before any skill-specific trust decision is made.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Even for the update-check path, the skill points users to an unpinned npx skills check, which still executes remote package code selected at runtime. While less immediately dangerous than installation, it preserves the same supply-chain attack surface.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The unpinned npx skills update command combines remote code execution risk with package update behavior, increasing exposure to malicious or breaking upstream releases. In this skill's context, users are encouraged to trust the ecosystem broadly, which amplifies the danger of unreviewed updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This search instruction again relies on unpinned npx skills, so simply looking for skills requires executing a mutable remote package. Because the skill is framed as routine discovery assistance, users may run it frequently and without scrutiny, increasing the practical risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The example search flow normalizes unpinned execution for common user requests, reinforcing insecure operational habits. If the CLI package or dependency tree is compromised, these examples provide a ready-made path to execute attacker-controlled code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This line repeats the same unpinned npx skills pattern in an installation-discovery context, where users are primed to take further package actions. The combination of search and install guidance magnifies the consequences of a compromised CLI package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Another unpinned CLI example appears in a context that encourages immediate execution based on user need. Since npx resolves and runs current package code, the lack of version pinning undermines reproducibility and creates supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install instruction npx skills add <owner/repo@skill> uses an unpinned CLI while also pointing at third-party sources, creating two independent trust boundaries. An attacker could abuse either the CLI distribution path or a returned skill source to achieve code execution or persistence.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This 'offer to install' step instructs the agent to run an unpinned npx command on the user's behalf, which is especially risky because it moves from advice to execution. In agent contexts, automating remote package execution without version pinning or trust review can directly compromise the host environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation instructions recommend -g -y without warning the user that this performs global, auto-confirmed installation. That suppresses an important human review step and increases blast radius by making persistent system-level changes, which is especially dangerous when combined with third-party skill installation and an unpinned CLI.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The command npx skills add <owner/repo@skill> -g -y is unpinned and also performs a global, non-interactive install, making any compromise more impactful and easier to trigger. This is particularly dangerous because it both executes remote package code and installs additional capability with reduced user friction and oversight.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Even the fallback guidance to create a new skill uses unpinned npx, preserving the same remote execution and reproducibility problems. While this is less directly harmful than auto-installing a third-party skill, it still conditions users to run mutable package code without verification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This final unpinned npx skills init example carries the same supply-chain risk as prior references, though in a creation rather than installation workflow. The repeated pattern across the skill increases likelihood of habitual unsafe use.

Content

No source excerpt is available for this finding.