Back to skill

Security audit

Space Query Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed query-building skill for asset-discovery platforms, with install and web-lookup caveats but no inspected malicious code, persistence, or credential handling.

Before installing, verify the repository and consider pinning to a reviewed commit or version because the documented install commands use mutable remote sources. When using the skill, treat generated queries as dual-use and run them only for authorized research or assets you are allowed to investigate; allow live CVE web lookups only when appropriate for your environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:17
Finding

Unpinned Remote Installation and Package Execution

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 17–31
Vulnerability Type: Supply-chain exposure through mutable, unverified remote installation sources
Risk Level: Medium

Vulnerable Code

bash
### Claude Code
# Clone the repository
git clone https://github.com/gandli/space-query-skill.git ~/.claude/skills/space-query-skill

### Claude Code Plugin
/plugin marketplace add gandli/space-query-skill
/plugin install space-query-skill@gandli

### Other
# Using skills CLI (recommended)
npx skills add gandli/space-query-skill

Technical Analysis

The documented installation methods retrieve content from mutable third-party sources without pinning an immutable Git commit, an exact package version, or a signed release. No checksum or signature verification is required before the retrieved content is installed.

The npx command presents additional exposure because it may download and execute an unpinned npm package. The Git and plugin installation methods place remotely controlled Skill content into an agent environment, where altered instructions may subsequently be loaded as trusted Skill instructions.

This finding is limited to the installation guidance. The audited artifact itself contains no executable scripts, embedded malicious code, persistence mechanisms, credential theft, or confirmed malicious payload.

Attack Path

  1. An attacker compromises the referenced GitHub account or repository, npm package or package namespace, or plugin marketplace entry.
  2. The attacker replaces the legitimate package content with malicious Skill instructions or executable components.
  3. A user follows one of the documented installation commands.
  4. The installation client retrieves the attacker-controlled latest version because no immutable version or digest is specified.
  5. The altered package is installed into the user's agent environment.
  6. The agent later loads or invokes the compromised Skill, allowing the malicious content to act w ...[truncated 772 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin Git installation instructions to a reviewed commit hash or immutable signed release tag.
  2. Publish SHA-256 checksums or cryptographic signatures for release artifacts and require verification before installation.
  3. Pin the Skill and CLI package to exact versions rather than resolving the latest available version.
  4. Avoid direct execution through unpinned npx. Prefer a locally installed, verified CLI or use npx --no-install after validating the package and lockfile.
  5. Document the expected repository owner, package name, release digest, and signature-verification procedure to reduce namespace-confusion and account-compromise risks.
  6. Recommend reviewing the downloaded Skill manifest, instructions, and scripts before enabling it in an agent environment.
  7. Where supported, install Skills with restricted tool permissions and require explicit approval before running newly introduced scripts or network operations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx skills add gandli/space-query-skill without pinning a specific package version. npx resolves and executes package code dynamically, so a future malicious or compromised package release could run arbitrary code on the user's machine during installation. In a security-oriented skill that may be used by technically privileged operators, this supply-chain risk is more concerning because users are more likely to execute setup commands verbatim.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list ends with broad catch-all wording such as 'or similar queries,' which can cause the skill to activate for loosely related security topics well beyond its intended scope. In a skill that helps build asset-discovery and vulnerability-search queries, over-triggering increases the chance of unintended assistance for reconnaissance-oriented requests and can bypass more appropriate routing or user clarification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the agent to 'ALWAYS use WebSearch first' for CVE handling, forcing an external lookup behavior regardless of user consent, runtime policy, or environment constraints. This can lead to unapproved outbound access, privacy/compliance issues, and unsafe dependence on potentially untrusted third-party sources such as blogs or PoC repositories when generating security-relevant queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON file contains all user-facing eval prompts and expected outputs in Chinese, but nowhere in the file indicates that the skill is region-specific or that users may choose another language. That can violate a language/locale policy when a skill implicitly forces one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown reference contains natural-language content in Chinese such as "IPv4 C段" without indicating that the skill is intended for Chinese-speaking users or offering an English-only alternative. Under the policy for language/locale constraints, forcing or assuming a specific language without opt-in can be a documentation-level policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example value "网络空间测绘" is presented as content users may search for, but the file does not explain whether Chinese-language usage is optional, required, or region-specific. Because the document mixes locales without guidance, it can violate organizational language-choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The category example uses the Chinese term "服务" in an otherwise mostly English reference. Without an explicit statement that the platform examples are multilingual or China-focused, this creates an undocumented language assumption.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The country field example includes both "CN" and "中国", showing locale-dependent values but offering no guidance on when each form should be used. This can create an implicit language requirement or confusion about accepted locales.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The login-page examples use Chinese text such as "登录" alongside English terms like "admin", but the document never states whether these are optional multilingual examples or a required language context. That omission can be treated as a language-policy issue because the user is not given clear locale guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The webcam search examples use the Chinese vendor name "海康威视" without any explanation of the intended audience or locale. In a general-purpose reference, this can amount to an undocumented language assumption.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.