Back to skill

Security audit

Astro Starlight

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Astro Starlight documentation-site helper, with visible but typical project setup and troubleshooting commands that users should run cautiously.

Before installing or using this skill, treat its shell commands as examples: run package-manager commands only in the intended project, avoid sudo, consider pinning versions for reproducibility, inspect processes before killing them, and verify your current directory before any rm -rf cleanup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Remote Package Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location:

  • SKILL.md:42-45
  • references/project-setup.md:17-30
  • references/project-setup.md:41-43
  • references/project-setup.md:239-242
  • references/deployment-and-advanced.md:26-45
  • references/styling-and-theming.md:124-138
  • references/troubleshooting.md:391-393
  • references/troubleshooting.md:423-429

Vulnerability Type: Execution of unpinned third-party npm packages
Risk Level: Medium

Vulnerable Code

SKILL.md:42-45:

bash
npm create astro@latest -- --template starlight

references/project-setup.md:17-30:

bash
# npm
npm create astro@latest -- --template starlight

# pnpm
pnpm create astro --template starlight

# yarn
yarn create astro --template starlight
bash
npm create astro@latest -- --template starlight/tailwind

references/project-setup.md:41-43:

bash
npx astro add starlight

references/project-setup.md:239-242:

bash
npx @astrojs/upgrade

references/deployment-and-advanced.md:26-45:

bash
npx astro add vercel
bash
npx astro add netlify
bash
npx astro add cloudflare

references/styling-and-theming.md:124-138:

bash
npm create astro@latest -- --template starlight/tailwind
bash
npx astro add tailwind
bash
npm install @astrojs/starlight-tailwind

references/troubleshooting.md:391-393:

bash
npx @astrojs/upgrade

references/troubleshooting.md:423-429:

bash
npx astro --version
npm list @astrojs/starlight
bash
npx @astrojs/upgrade

Technical Analysis

The Skill repeatedly recommends npm create, npx, pnpm create, and yarn create commands without pinning reviewed package versions. The @latest specifier explicitly retrieves whichever release is current when the command is run. Depending on package-manager behavior and local inst ...[truncated 2049 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace floating versions and @latest with explicitly reviewed versions, for example:

    bash
    npm create astro@5.14.1 -- --template starlight
    npx @astrojs/upgrade@0.4.4
    

    The exact versions should be selected and updated through the project's dependency-review process.

  2. Install required tools as declared project dependencies rather than retrieving them ad hoc:

    bash
    npm install --save-dev astro@<reviewed-version>
    
  3. Commit a reviewed lockfile and use reproducible installation commands such as:

    bash
    npm ci
    
  4. Require lockfile integrity checks in CI and reject unexpected dependency-tree changes.

  5. Review package provenance, publisher identity, release signatures where available, and lifecycle scripts before approving upgrades.

  6. Consider disabling lifecycle scripts during initial inspection:

    bash
    npm install --ignore-scripts
    

    Enable required scripts only after reviewing them.

  7. Document that package-manager commands must run as an unprivileged user in a project-scoped environment, never with sudo.

  8. For automated agents, require explicit user approval before downloading or executing a package version that is not already present in the reviewed lockfile.

T09 · Insecure Skill Coding Practices

Note
Location
references/troubleshooting.md:66
Finding

Unverified Termination of the Process Occupying Port 4321

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md:66-71
Vulnerability Type: Unsafe process termination command
Risk Level: Low

Vulnerable Code

bash
# Use a different port
npm run dev -- --port 3001
# Or kill the existing process
lsof -ti:4321 | xargs kill

Technical Analysis

The pipeline passes every process identifier returned by lsof -ti:4321 directly to kill without displaying process details, validating ownership or command identity, limiting the result to the intended Starlight development server, or requesting confirmation.

Port occupancy alone does not establish that the process belongs to the current project. Another development service or unrelated application may legitimately use port 4321. The command therefore permits accidental termination of unrelated processes owned by the invoking user.

In common operating-system configurations, an unprivileged user can signal only their own processes. Running the instruction with elevated privileges would expand the affected scope, although the Skill does not instruct users to use sudo.

Attack Path

  1. An unrelated process is listening on or otherwise reported as using port 4321.
  2. A user encounters a port-conflict error while following the troubleshooting guide.
  3. The user runs lsof -ti:4321 | xargs kill without inspecting the returned process.
  4. xargs supplies the returned PID or PIDs directly to kill.
  5. The unrelated process receives the termination signal and exits or loses in-progress work.

An attacker with the ability to influence local process state could intentionally place a valuable same-user process on the target port and induce the user to follow the troubleshooting step, but accidental misuse is the more likely scenario.

Impact Assessment

The direct impact is local availability loss and possible loss of unsaved work. The command can terminate one or more processes associate ...[truncated 407 chars]

Remediation
View remediation

Remediation Suggestions

  1. Retain use of an alternate port as the preferred non-destructive solution:

    bash
    npm run dev -- --port 3001
    
  2. Instruct the user to inspect the process before taking action:

    bash
    lsof -nP -iTCP:4321 -sTCP:LISTEN
    
  3. Verify the PID, owner, executable, and command line:

    bash
    ps -fp <PID>
    
  4. Terminate only a PID confirmed to belong to the current project:

    bash
    kill <CONFIRMED_PID>
    
  5. Require explicit user confirmation before an agent sends a signal to any process.

  6. Do not recommend sudo, kill -9, or broad process-name matching as initial remediation.

  7. If automation is necessary, verify the process working directory and executable identity before termination, and abort when multiple or ambiguous matches are found.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (19)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/components.md (reported line 80)May include surrounding context.

md
<TabItem label="pnpm">pnpm build</TabItem>
</Tabs>

<!-- Later on the same page, these stay synced: -->
<Tabs syncKey="pkg">
  <TabItem label="npm">npm run dev</TabItem>
  <TabItem label="pnpm">pnpm dev</TabItem>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 379)May include surrounding context.

Fix:

bash
# Clear Astro's type cache
rm -rf .astro/
npm run build

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 414)May include surrounding context.

Fix:

bash
# Clear Astro's type cache
rm -rf .astro/
npm run build

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'Full reset' block combines multiple recursive deletions (node_modules, package-lock.json, .astro, dist) with no warning, backup advice, or working-directory constraint. In a troubleshooting skill, this is especially dangerous because frustrated users are primed to execute 'nuclear' steps immediately, risking accidental project damage and dependency-state loss.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger guidance is excessively broad, explicitly instructing activation even for generic phrases like 'docs site' or 'documentation website' and positioning Starlight as the default approach. In an agent system, this can cause inappropriate skill selection, override more suitable skills, and steer users toward actions or tooling they did not request, increasing the chance of confused-deputy behavior or policy bypass through misrouting.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/project-setup.md (reported line 161)May include surrounding context.

md
head: [
        {
          tag: 'script',
          attrs: { src: 'https://analytics.example.com/script.js', defer: true },
        },
      ],

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The troubleshooting guide recommends rm -rf node_modules package-lock.json without warning that it irreversibly deletes dependency state and lockfile pinning. In a docs/troubleshooting skill, users are likely to copy-paste commands directly, so presenting destructive cleanup without caution increases the chance of accidental data loss or unintended environment drift.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command lsof -ti:4321 | xargs kill can terminate whichever process currently owns the port, without confirming that it is the intended dev server. In a troubleshooting document, users may run it verbatim and accidentally kill unrelated local services or important processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction to rm -rf .astro/ is a destructive deletion step presented as a routine cache fix without warning. Although .astro/ is typically regenerable, users may generalize the pattern or run it from the wrong directory, making the omission of caution unsafe in copy-paste-oriented troubleshooting content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The recovery step again instructs users to delete .astro/ with no cautionary note or path validation. Even if the directory is disposable in normal cases, repeating destructive patterns without guardrails in troubleshooting documentation encourages unsafe operator behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.