Back to skill

Security audit

find-skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a skill-discovery helper, but it steers agents toward unpinned package execution and global, prompt-skipping installation of third-party skills.

Review this skill carefully before installing. It is not evidence of malware, but it can lead your agent to run a dynamically resolved CLI and install third-party skills globally without interactive confirmation. Prefer pinned CLI versions, explicit approval before installs, and local or scoped installs where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The metadata description says this skill should be used whenever users ask broad questions like 'how do I do X' or express interest in extending capabilities. Such wide triggers can cause the skill to activate in many normal conversations, leading the agent to introduce package-search and installation guidance when the user did not clearly ask to execute third-party tooling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'When to Use This Skill' section uses ambiguous conditions like 'can you do X' and 'wish they had help,' which overlap with ordinary assistance requests. In practice this can over-trigger the skill and steer users toward third-party package installation flows, increasing unnecessary exposure to supply-chain and consent issues.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a package version. Because npx may fetch the latest published package at execution time, users could unknowingly run changed or compromised code from the registry or a dependency update. In a skill whose purpose is discovery and installation of more code, this increases supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command reference uses npx skills without a fixed version, so execution depends on whatever package version is current when the user runs it. That exposes users to registry/package compromise or breaking behavior changes outside the author's control.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

An unpinned npx package invocation causes remote code to be resolved dynamically at runtime. If the package or a dependency is hijacked, this skill would direct users to execute attacker-controlled code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Referencing npx skills update without version pinning normalizes a pattern where users execute a moving target from the package ecosystem. This is particularly risky because it combines dynamic package resolution with update behavior, magnifying supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The example search command invokes npx skills without constraining the package version. Even though it is a search operation, the risk exists before the subcommand runs because the package itself must be downloaded and executed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This line promotes an unpinned npx skills find example. Any such invocation can execute newly published code, making the skill a vector for accidental supply-chain execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The command example relies on npx to fetch the current package version, which can change unexpectedly or be compromised. Since users are encouraged to copy/paste it, the risk is practical rather than theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This example again instructs users to execute an unpinned package through npx. The skill context makes this more dangerous because it acts as a package-discovery/install guide, so users may be repeatedly exposed to runtime-fetched code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install command npx skills add ... is unpinned and directly leads to installation of additional code. That combines two layers of trust—first the transient CLI package, then the selected skill package—without version locking at the CLI layer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill recommends npx skills add <owner/repo@skill> -g -y and explains the flags functionally, but omits a clear warning that this performs a global install and suppresses confirmation prompts. That can lead users to authorize persistent system changes and execution of third-party code without informed consent, especially risky in a skill that discovers arbitrary packages.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line tells the agent/user to run npx skills add <owner/repo@skill> -g -y without pinning the CLI version. Because it performs installation, potentially globally and non-interactively, compromise of the fetched CLI could yield immediate arbitrary code execution with persistent system impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The advice references npx skills again without version pinning, reinforcing insecure operational habits. Repetition across the document increases the likelihood users will execute an unreviewed package version.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The npx skills init example is unpinned, so even a benign initialization workflow requires executing a package version resolved at runtime. That creates a supply-chain entry point unrelated to the user's actual task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.