Back to skill

Security audit

SmartPage

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent document-formatting purpose, but it asks agents to install and run mutable third-party code with broad local effects.

Review this before installing. Use it only in a disposable or restricted workspace, inspect and pin the SmartPage repository before running npm install, avoid sensitive documents unless you control the temp and output locations, and stop the dev server when finished.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:13
Finding

Unpinned Remote Repository Retrieval and Unsafe Dependency Installation

Content
View full analysis
Remediation
View remediation
``` 2. Verify the checked-out commit or release against a trusted digest or signature before executing installation commands. 3. Require and review a committed lockfile, then replace `npm install` with deterministic installation: ```bash npm ci --ignore-scripts ``` 4. Audit all dependencies and lifecycle scripts. If lifecycle scripts are operationally required, explicitly allow only reviewed scripts rather than enabling arbitrary package hooks. 5. Vendor the reviewed implementation with the Skill or distribute a signed, versioned release artifact so that the executed code matches the audited code. 6. Run installation and rendering in a restricted environment with: - A dedicated unprivileged account. - Minimal filesystem access. - No unnecessary credentials or secrets. - Restricted outbound network access. - A disposable workspace or container. 7. Re-audit the pinned source and dependency lockfile whenever the approved version changes. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to clone and install code from an external GitHub repository and later run a local development server and open a browser. That materially expands the capability surface from simple document formatting into arbitrary third-party code execution and browser interaction, which creates supply-chain, local exposure, and unexpected-action risks not clearly required by the stated skill purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow instructs writing user content to temporary files and exporting generated artifacts to the user's desktop without any notice, consent, retention policy, or cleanup guidance. User documents may contain sensitive data, and saving them to broadly accessible locations or leaving temp files behind can expose private information to other local users, backup systems, or unrelated applications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction says to ALWAYS ask the user a fixed Chinese-language question after delivery. This forces a specific language regardless of the user's preferred locale and does not provide opt-in, fallback behavior, or justification for a Chinese-only interaction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.