Back to skill

Security audit

One-shot perfect landing page

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent landing-page redesign skill; the reviewed files fit that purpose, with a caution that the README shows an unpinned installer command.

Before installing, prefer a pinned installer version or reviewed commit if available, and use this skill only when you want broad landing-page edits. Expect it to modify page copy, styling, Tailwind configuration, and frontend components.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:47
Finding

Unpinned Third-Party Installer and Mutable Skill Source

Content
View full analysis

Vulnerability Details

File Location: README.md, line 47
Vulnerability Type: Supply-chain exposure through unpinned third-party code
Risk Level: Medium

Vulnerable Code

bash
npx skills add Flacko2048/million-dollar-landing

Technical Analysis

The documented installation command invokes the skills package through npx without specifying an audited package version. It also identifies the Skill through a mutable GitHub owner/repository reference rather than an immutable commit SHA or signed release.

Consequently, the command may resolve different installer code or Skill content over time. The local files reviewed in this audit therefore do not necessarily represent the files that a user will receive when running the command later. If the npm package, npm publisher account, GitHub account, or referenced repository is compromised, an attacker could distribute altered instructions or executable content through the legitimate-looking installation command.

This is a supply-chain weakness rather than evidence that the currently reviewed React components contain malicious code.

Attack Path

  1. An attacker compromises the npm package, its publisher account, the referenced GitHub account, or the repository.
  2. The attacker publishes a malicious installer version or modifies the repository's current revision.
  3. A user follows the README and runs the unpinned npx skills add Flacko2048/million-dollar-landing command.
  4. npx resolves and executes the mutable third-party installer, which retrieves or installs the current mutable Skill content.
  5. Installer-level malicious code may execute immediately with the invoking user's privileges. Alternatively, malicious Skill instructions or files may become active when the installed Skill is subsequently loaded or used.

Impact Assessment

Installer-level compromise could execute code with the privileges of the user running npx, potentially allow ...[truncated 744 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills installer to a specific audited version:
    bash
    npx skills@<audited-version> add ...
    
  2. Pin the Skill source to an immutable commit SHA or a cryptographically signed release instead of relying on the repository's current default branch.
  3. Publish SHA-256 checksums or signed provenance for released Skill archives and verify them before installation.
  4. Prefer downloading and reviewing the Skill locally before installing it, particularly in environments containing source-control, cloud, package-registry, or deployment credentials.
  5. Run installation with least privilege in an isolated environment. Do not use sudo, and avoid exposing unrelated secrets through environment variables.
  6. Document the exact installer version and Skill commit that correspond to the audited release.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to run npx skills add Flacko2048/million-dollar-landing without pinning a specific version or immutable reference. That means installation may fetch whatever code is current at execution time, creating a supply-chain risk if the package, tool, or referenced skill content is updated maliciously or compromised later.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's 'Use when' guidance includes very broad, common phrases such as 'improve landing page', 'rewrite copy', and 'fix mobile layout'. This can cause the skill to be invoked in situations beyond the author's intended scope, increasing the chance it rewrites unrelated content or applies sweeping UI/code changes without sufficient user intent verification. In context, the skill has write/edit capabilities, which makes accidental over-triggering more risky than a purely informational skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language guidance and code example specify Google fonts with subsets: ['latin'], which bakes in a locale/language constraint rather than leaving room for the user's language needs. There is no opt-in, alternative subset guidance, or justification that this skill is intended only for Latin-script sites.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.