Back to skill

Security audit

Acp Team

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for multi-agent coordination, but it relies on unpinned global npm installs and can spawn agents and create persistent project state with limited guardrails.

Review the npm packages and consider installing pinned, project-local versions before use. Only run initialization, spawn, task mutation, and inbox-draining commands in a project where creating .team/ and .tasks/ state and running additional agent sessions is acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
skill.md:42
Finding

Unpinned Global Installation of Third-Party npm Packages

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 42–47
Vulnerability Type: Unpinned third-party dependencies installed globally
Risk Level: Medium

Vulnerable Code

bash
npm install -g acp-team
bash
npm install -g acpx

Technical Analysis

The installation instructions retrieve and execute the latest registry-resolved versions of acp-team and acpx. The project provides no exact versions, lockfile, integrity hashes, vendored source, or other mechanism for verifying the installed artifacts.

npm installation can execute package lifecycle scripts under the installing user's account. Because -g installs packages globally, their command-line executables become available system-wide for that user or installation prefix. The audited project contains only skill.md; consequently, the source and lifecycle behavior of these external packages could not be verified within the audit scope.

This creates supply-chain exposure: a compromised publisher account, malicious release, package takeover, or unexpected upstream update could change the code executed by users after this skill has already been reviewed.

Attack Path

  1. An attacker compromises an upstream package, publisher account, or release process for acp-team or acpx.
  2. The attacker publishes a malicious version under the package's existing name.
  3. A user follows the documented commands without specifying a reviewed version.
  4. npm resolves and downloads the mutable malicious release.
  5. Package lifecycle scripts may execute during installation with the installing user's privileges.
  6. The installed global executable can subsequently run attacker-controlled logic whenever the documented workflow invokes it.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user performing the installation. Potential effects include reading or modifying user-accessible files, accessing environment variables and credentia ...[truncated 516 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin both dependencies to exact, reviewed versions rather than resolving the latest release:

    bash
    npm install --save-exact acp-team@<reviewed-version> acpx@<reviewed-version>
    
  2. Prefer project-local installation and invoke the binaries through npm exec or package scripts instead of installing them globally.

  3. Commit a lockfile generated from reviewed artifacts and enforce lockfile-based installation with npm ci.

  4. Verify package provenance, publisher identity, registry source, and integrity metadata before installation.

  5. Audit the packages' source, transitive dependencies, binaries, and lifecycle scripts for each approved release.

  6. Where compatible with the packages, use --ignore-scripts during installation and explicitly run only reviewed setup operations.

  7. Run the tools under a dedicated, least-privileged account or sandbox without unnecessary access to credentials, sensitive files, or administrative resources.

  8. Establish an update-review process so version changes and lockfile modifications require security review before deployment.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases such as "team," "multi-agent," and "inbox," which can cause the skill to activate in contexts where the user did not intend to invoke filesystem-backed coordination behavior. In this skill, unintended activation is more dangerous because it can lead the agent to create local .team/.tasks state, spawn agents, or drain inbox messages without clear user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents commands that create persistent local files under .team/ and .tasks/ and includes an inbox command that drains messages, but it does not warn users about these side effects. In a coordination skill, this omission is security-relevant because users may unknowingly lose queued messages or allow unexpected local state creation that affects project contents and downstream automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.