Back to skill

Security audit

Timeplus Design

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Timeplus UI design-system skill with optional tooling notes, not hidden runtime behavior.

Safe to install as a design reference. Before running the optional npx commands, pin a reviewed @google/design.md version or run them in a restricted project environment, and adapt the sample input component to bind labels with htmlFor/id.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:76
Finding

Unpinned npm Package Is Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15 and 76–82
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

At line 15:

yaml
Optional: validate DESIGN.md with `npx @google/design.md lint DESIGN.md`
(requires Node.js).

At lines 76–82:

bash
npx @google/design.md lint DESIGN.md

You can also export the tokens to Tailwind or W3C DTCG format:

bash
npx @google/design.md export --format css-tailwind DESIGN.md > theme.css

Technical Analysis

The documented commands invoke @google/design.md through npx without specifying an exact package version or verifying an integrity hash. If the package is not already available locally, npx can resolve and download a mutable version from the configured npm registry before executing its binary.

Consequently, the code executed by these commands can change after the Skill has been audited. A compromised package release, maintainer account, transitive dependency, or registry response could introduce malicious code. Depending on npm configuration and the package contents, installation lifecycle scripts may also execute during package acquisition.

Although these commands are described as optional, users following the documented validation or export procedure are exposed to this supply-chain risk. The export command also redirects output to theme.css, which overwrites that file if it already exists.

Attack Path

  1. An attacker compromises the npm package, a maintainer account, a transitive dependency, or the package-resolution infrastructure.
  2. The attacker publishes or serves a malicious version under the expected @google/design.md package name.
  3. A user follows the Skill documentation and runs one of the unversioned npx commands.
  4. npx resolves and downloads the mutable package version from the configured registry.
  5. Malicious package installation logic or the package executable runs with the privileges of ...[truncated 776 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed, exact version rather than allowing npx to resolve the latest release:

    bash
    npx --yes @google/design.md@EXACT_REVIEWED_VERSION lint DESIGN.md
    npx --yes @google/design.md@EXACT_REVIEWED_VERSION export --format css-tailwind DESIGN.md > theme.css
    
  2. Prefer declaring the package in a development dependency manifest and committing a lockfile containing integrity metadata. Invoke the lockfile-resolved local binary through a package script.

  3. Review the selected package version and its transitive dependency tree before use. Update it through a controlled dependency-review process.

  4. Disable lifecycle scripts during installation where compatible with the package:

    bash
    npm install --ignore-scripts
    
  5. Execute optional tooling in a restricted environment with minimal filesystem access, no unnecessary credentials, and limited outbound network connectivity.

  6. Clearly disclose that the validation and export procedures download and execute third-party code and are not purely documentation-only operations.

  7. Avoid accidental output-file replacement by checking whether theme.css exists or writing to a temporary file before performing an explicit atomic replacement.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This natural-language requirement forces a specific language/locale-related presentation choice ('Inter, exclusively') across the whole application. Under the policy category, prescriptive locale/language-style constraints should either offer user choice or be clearly justified as necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file includes a natural-language rule stating 'Font: Inter only,' which imposes a fixed presentation standard without noting any user opt-in or exception. Under the policy criteria, forced language/locale-style constraints in natural-language instructions can be findings when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s accessibility section explicitly requires associating labels to inputs via for/id, but the React Input example renders a plain without htmlFor and an without a matching id. This can break screen-reader form navigation and reduce click-to-focus behavior, causing consumers of this reference implementation to propagate inaccessible form controls into production UI.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.