Back to skill

Security audit

Design Md

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it may install global software and run diagram tools without clearly asking first.

Install only if you are comfortable with the agent creating .mddoc files, running local rendering commands, and potentially installing mddoc-cli globally from npm. Prefer manually installing reviewed, pinned tooling or running it in a contained project environment before using the skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25–29
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

markdown
若 `mddoc` 未安装:

```bash
npm install -g mddoc-cli
text

### Technical Analysis

The skill directs the agent to install `mddoc-cli` from the npm registry without specifying a reviewed version, lockfile, or integrity hash. Consequently, the package content installed at execution time can differ from the content that was available when the skill was audited.

npm installation can execute package lifecycle scripts with the permissions of the account running the agent. The `-g` option also places the package in the configured global npm prefix rather than isolating it within the current project. If the package, one of its transitive dependencies, or its publishing account is compromised, installation could execute attacker-controlled code and modify globally available user tooling.

### Attack Path

1. A user invokes the skill to generate a diagram.
2. The dependency check determines that the `mddoc` executable is unavailable.
3. The agent follows the skill instructions and executes `npm install -g mddoc-cli`.
4. npm resolves the current package release and its transitive dependencies from the registry without an audit-pinned version or integrity policy.
5. A compromised or malicious package version executes an npm lifecycle script during installation.
6. The script operates with the invoking account's privileges and can access that account's files, environment variables, network connectivity, and writable npm global prefix.

### Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the account running the installation. An attacker could read or modify files accessible to that account, access exposed environment variables, communicate over the network, and replace or modify executables in the writa
...[truncated 349 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin mddoc-cli to a specific reviewed version rather than installing the latest release implicitly.
  • Prefer a project-local dependency recorded in package.json and a committed lockfile instead of global installation.
  • Use a reproducible installation command such as npm ci with lockfile integrity metadata.
  • Verify the package publisher, provenance, signatures where available, and expected integrity before installation.
  • Review the package and its transitive dependencies, including npm lifecycle scripts.
  • Disable lifecycle scripts during installation when they are unnecessary, for example with --ignore-scripts, after confirming that this does not prevent legitimate operation.
  • Require explicit user approval before downloading or installing external software.
  • Execute diagram tooling in a sandbox or container with minimal filesystem access, no unnecessary credentials, and restricted network access.
  • Document an approved installation procedure separately instead of automatically directing the agent to modify global tooling.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common requests such as 'insert chart' or 'diagram', which can cause the skill to activate unexpectedly in ordinary Markdown-editing contexts. Because the skill is allowed to write files and invoke shell commands, accidental activation expands the attack surface and may lead to unanticipated filesystem changes or command execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and examples are written to operate in Chinese and specify Chinese trigger phrases, but they do not indicate that language choice is optional or that the skill is intentionally limited to a Chinese-only context. This can violate language/locale policy when a skill implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to check for dependencies, install packages, create directories, write source files, and execute CLI tools, but it does not warn users that these side effects will occur. This is dangerous because users may believe they are requesting a simple formatting operation when the skill can modify the environment and run package-installation commands, increasing the risk of surprise changes and supply-chain exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.