Back to skill

Security audit

Astro - Advanced Developer

Security checks for vulnerabilities and agentic risk

Overview

This is an Astro web-development guidance skill with some copy-paste security cautions, but no hidden or automatic harmful behavior.

Before installing, treat this as normal Astro guidance but do not let an agent run npm/npx commands, community templates, deletions, or deployment commands without review. Replace sample secrets with placeholders, keep real secrets in your hosting platform or secret manager, and avoid logging secret values.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:57
Finding

Unpinned Third-Party Packages Are Downloaded and Executed

Content
View full analysis
Remediation
View remediation
`. - Declare tools as project development dependencies and execute their lockfile-resolved local binaries. - Commit and review the package lockfile, then use `npm ci` in automated environments. - Review dependency changes and lifecycle scripts before installation. - Require explicit user approval before an agent downloads or executes packages. - Use registry integrity, provenance, and allowlisting controls where available. - Run installation and build operations in an isolated environment with minimal credentials and filesystem access. ]]>

T08 · Insecure Dependencies

Warning
Location
references/setup-and-structure.md:16
Finding

Project Creation Permits an Arbitrary Unpinned Community Template

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
references/deployment.md:214
Finding

Environment Variable Examples Encourage Storing Production Secrets in Project Files

Content
View full analysis
Remediation
View remediation
`. - Recommend setting production secrets through the hosting platform's secret store. - Include a secure `.gitignore` example that excludes `.env`, `.env.*`, and other secret-bearing files while permitting a sanitized `.env.example`. - Keep only variable names and non-sensitive sample values in repository files. - Use short-lived, narrowly scoped credentials where supported. - Add automated secret scanning to local hooks and CI. - Rotate any credential immediately if it is committed or otherwise disclosed. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
references/troubleshooting.md:303
Finding

Troubleshooting Example Prints Server-Side Secrets to Logs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (48)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
- `references/rendering-modes.md` — SSG vs SSR vs Hybrid, when to use each, caching strategies

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployment.md (reported line 216)May include surrounding context.

Defining variables

bash
# .env (development)
PUBLIC_API_URL=https://api.dev.example.com
SECRET_API_KEY=sk-dev-12345

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployment.md (reported line 220)May include surrounding context.

PUBLIC_API_URL=https://api.dev.example.com SECRET_API_KEY=sk-dev-12345

.env.production (production build)

PUBLIC_API_URL=https://api.example.com SECRET_API_KEY=sk-prod-67890

text

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/islands-and-vue.md (reported line 152)May include surrounding context.

Basic Vue island

vue
<!-- src/components/Counter.vue -->
<script setup lang="ts">
import { ref } from 'vue';

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/islands-and-vue.md (reported line 309)May include surrounding context.

``` This is the #1 Astro support question. The component renders HTML fine but click handlers, reactive state, and lifecycle hooks don't run.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 32)May include surrounding context.

Fix:

astro
<!-- Before: static HTML only -->
<Counter />

<!-- After: hydrated and interactive -->

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 87)May include surrounding context.

md
npm ls --depth=0

# Clear caches
rm -rf node_modules/.astro
rm -rf node_modules/.vite

# Reinstall

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 88)May include surrounding context.

md
# Clear caches
rm -rf node_modules/.astro
rm -rf node_modules/.vite

# Reinstall
rm -rf node_modules

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 234)May include surrounding context.

md
### Content not updating in dev
- Restart the dev server after changing `config.ts`
- Run `npx astro sync` after schema changes
- Clear `.astro` cache: `rm -rf node_modules/.astro`

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 438)May include surrounding context.

md
### HMR (Hot Module Replacement) not working
- Some changes require a full restart (config changes, new content collections)
- Clear the Vite cache: `rm -rf node_modules/.vite`
- Check for circular imports

### Dev server crashes on save

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger criteria are unusually broad, including indirect mentions like generic framework integrations, troubleshooting, and even implied .astro syntax concepts. In an agentic environment, overbroad activation can cause the skill to run in unrelated contexts, increasing the chance of inappropriate instructions, mis-scoped file generation, or unsafe automation based on weak keyword matches.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/content-and-data.md (reported line 163)May include surrounding context.

astro
---
// This runs at BUILD TIME, not in the browser
const res = await fetch('https://api.example.com/products');
const products = await res.json();
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/content-and-data.md (reported line 185)May include surrounding context.

astro
---
// This runs at BUILD TIME, not in the browser
const res = await fetch('https://api.example.com/products');
const products = await res.json();
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/performance.md (reported line 257)May include surrounding context.

astro
---
// This runs at BUILD TIME, not in the browser
const res = await fetch('https://api.example.com/products');
const products = await res.json();
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/performance.md (reported line 258)May include surrounding context.

astro
---
// This runs at BUILD TIME, not in the browser
const res = await fetch('https://api.example.com/products');
const products = await res.json();
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation includes realistic-looking secret values in .env and .env.production examples without an explicit warning not to commit secrets or use real credentials. In a deployment-focused skill, users are likely to copy these patterns directly, increasing the chance of unsafe secret handling and accidental credential exposure in source control or build artifacts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/deployment.md:230