Back to skill

Security audit

Code Card Sync

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate stats-sync purpose, but it recommends recurring execution of an unpinned npm package and under-explains what local session data is uploaded.

Review carefully before installing. Prefer a pinned, reviewed Code Card CLI version, avoid printing the API key, confirm exactly what session data is uploaded, and do not add the cron jobs unless you accept unattended recurring syncs.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T06 · System Persistence

Error
Location
SKILL.md:55
Finding

Persistent Scheduled Execution of External Synchronization Commands

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:29
Finding

Runtime Download and Execution of an Unpinned npm Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:21
Finding

API Key Disclosed Through Configuration File Output

Content
View full analysis
/dev/null ``` If it prints `CC_API_KEY=cc_...`, skip to the **Sync** section. ``` ### Technical Analysis The setup check reads the complete `~/.claude/.codecard` file and writes it to standard output. The document explicitly expects the output to include a `CC_API_KEY` value. The operation only needs to determine whether valid-looking configuration exists, but instead reveals the credential itself. In an Agent workflow, command output may be copied into conversation context, execution logs, telemetry, terminal history, debugging records, or other retained systems. Redirecting standard error to `/dev/null` does not protect the secret because the file contents are emitted through standard output. ### Attack Path 1. The Agent follows the Skill's first-time setup instructions. 2. It executes `cat ~/.claude/.codecard 2>/dev/null`. 3. The complete API key is printed to standard output. 4. The output is ingested into the Agent context or retained by terminal, orchestration, telemetry, or audit logging systems. 5. A party with access to those records obtains the key. 6. The exposed credential may be reused against the associated service according to the permissions granted to that API key. ### Impact Assessment The direct impact is disclosure of the Code Card API credential to systems or individuals that can observe command output. The precise service-side privileges of the key are not documented in the audited file, so the maximum account impact cannot be established from the available evidence. At minimum, exposure may permit unauthorized use of the credential within its assigned scope. The issue also unnecessarily expands secret access from the local configuration file to every system that records the Agen ...[truncated 23 chars]
Remediation
View remediation
/dev/null ``` - Do not return matching content from the check. - Ensure the Agent reports only a boolean configuration state, such as “configured” or “not configured.” - Redact credentials from command output, logs, telemetry, and exception messages. - Store the credential with restrictive filesystem permissions and verify that the file is not readable by other users. - Prefer an operating-system credential store or secret-management facility over a plaintext configuration file where supported. - Provide key revocation and rotation instructions for users whose key may already have been exposed. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:29
Finding

Opaque Full Upload of Local Coding-Session Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
87% confidence
Finding

The skill instructs access to ~/.claude/.codecard, which is inside an agent configuration directory and may contain API credentials. Even though the example only reads a specific file, normalizing direct inspection of config directories increases the chance of credential disclosure in chat logs, terminal captures, or accidental over-broad file access patterns.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Check if already configured:

bash
cat ~/.claude/.codecard 2>/dev/null

If it prints CC_API_KEY=cc_..., skip to the Sync section.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states it syncs AI coding stats and sessions to an external service, but it does not provide a clear privacy warning describing what data leaves the machine, where it is sent, or how it is handled. Users may unknowingly expose sensitive coding metadata, prompts, filenames, or activity patterns to a third party without informed consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill instructs users to run npx code-card@latest, which fetches and executes the latest package version at runtime. This creates a supply-chain risk: if the package is compromised, typosquatted, or publishes a malicious update, arbitrary code would execute on the user's machine without review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command uses npx code-card@latest sync -i, which downloads and executes the newest published package version every time it runs. Because it is intended for repeated sync operations, it expands the attack surface for malicious package updates or registry compromise into a recurring remote-code-execution path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The full resync command again executes npx code-card@latest, inheriting the same unpinned package execution risk. A full sync may also process more local data, making a compromised package especially sensitive because it can access a broader set of coding-session information during execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The stats example uses npx code-card@latest, so even a read-oriented command still causes execution of unreviewed latest code from the registry. Although the functional purpose appears benign, it still grants arbitrary code execution capability to whatever package version is served at invocation time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The profile command also uses npx code-card@latest, preserving the same dynamic package execution risk. Even though the command's goal is just to open a profile, a compromised package could perform unrelated malicious actions locally before or instead of that behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The cron job message schedules recurring execution of npx code-card@latest sync -i, turning the unpinned supply-chain risk into an automated persistence mechanism. Once scheduled, any future malicious package update could execute regularly without additional user scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

This weekly cron example automates npx code-card@latest sync, creating a long-lived recurring path for unreviewed code execution from the package registry. The scheduled nature makes the context more dangerous than an interactive one-off command because compromise can trigger later and repeatedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.