Back to skill

Security audit

API Development

Security checks for vulnerabilities and agentic risk

Overview

This API-development skill is mostly coherent, but its examples include destructive API calls, credential-bearing requests, file uploads, and unpinned package execution without enough safety scoping.

Install only if you are comfortable treating this as a review-needed API helper. Use it against local or test APIs by default, avoid running destructive examples on production data, verify base URLs and resource IDs before mutation, keep real tokens and files out of shell history, and pin or lock npm-based CLI tools instead of running unversioned npx commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:334
Finding

Unpinned OpenAPI CLI Package Downloaded and Executed with npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:334-335
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code:

bash
# Using npx (no install needed)
npx @redocly/cli lint openapi.yaml

Technical Analysis

The Skill instructs users or agents to invoke @redocly/cli through npx without specifying a reviewed version. If the package is not already available locally, npx can retrieve it from the configured package registry and immediately execute its code. Because the package version and integrity are not pinned, the effective executable payload may change after the Skill has been reviewed.

This creates a supply-chain trust boundary: compromise of the package publisher, registry account, transitive dependency, or package-resolution configuration could result in arbitrary code execution. OpenAPI validation requires a parser or validator, but it does not require execution of an unversioned, remotely resolved package.

Attack Path

  1. An attacker compromises the package, one of its dependencies, its publisher account, or the registry/resolution path.
  2. The attacker publishes a malicious release that can be selected by an unversioned npx invocation.
  3. A user or agent follows the Skill and runs npx @redocly/cli lint openapi.yaml.
  4. npx downloads and executes the mutable package content.
  5. The malicious package executes with the permissions and environment of the invoking user or agent.

Impact Assessment

Successful exploitation could execute arbitrary commands under the invoking account. Accessible scope may include project source files, writable files owned by the user, environment variables, API credentials available to the process, and network resources reachable from the host. The command does not itself request elevated operating-system privileges, so impact is generally bounded by the invoking account and its sandbox. No evidence s ...[truncated 53 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the CLI to a specifically reviewed version rather than relying on the registry's current default version.
  • Declare the dependency in a project manifest and commit the corresponding lockfile with integrity metadata.
  • Install dependencies using a lockfile-enforcing command such as npm ci, then invoke the locally locked binary.
  • Configure an approved registry and apply package provenance, signature, and integrity verification where supported.
  • Require explicit user approval before downloading or executing a package that is absent locally.
  • Run validation in a restricted environment with minimal filesystem access, no unnecessary credentials, and limited network access.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:509
Finding

Unpinned WebSocket CLI Package Downloaded and Executed with npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:509
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code:

bash
- For WebSocket testing: `npx wscat -c ws://localhost:3000/ws`

Technical Analysis

The WebSocket testing guidance invokes wscat through npx without pinning a reviewed version. When the package is unavailable locally, npx can download it from the configured package registry and immediately run it. The content executed by this instruction can therefore change independently of the audited Skill.

Connecting to a local WebSocket endpoint is consistent with the Skill's API-testing purpose. The security issue is not that connection itself, but the avoidable execution of mutable third-party package code. A compromised release, dependency, publisher account, registry, or package-resolution configuration could turn the testing command into arbitrary local code execution.

Attack Path

  1. An attacker gains control over a package release, transitive dependency, publisher account, or registry/resolution path used for wscat.
  2. Malicious code is included in a version selected by the unpinned invocation.
  3. A user or agent follows the Skill and executes npx wscat -c ws://localhost:3000/ws.
  4. npx retrieves and runs the attacker-controlled package code.
  5. The payload operates with the permissions, environment, and resource access of the invoking process.

Impact Assessment

Exploitation could allow arbitrary code execution under the invoking user or agent account. Potentially exposed assets include project files, user-writable data, process environment variables, development credentials, and network services reachable from the host. The command does not request administrative privileges, so the obtainable scope depends on the invoking account and any applicable sandbox controls. The audit found no evidence of intentional malicious execu ...[truncated 20 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin wscat to an explicitly reviewed version.
  • Prefer a project-declared development dependency installed from a committed lockfile with integrity metadata.
  • Invoke the locked local binary instead of permitting npx to resolve the latest registry version.
  • Require confirmation before any package download or first-time execution.
  • Use an approved registry and verify package provenance and integrity where available.
  • Execute the client with minimal filesystem permissions, without unrelated secrets in its environment, and with network access restricted to the intended test endpoint.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (24)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The test runner includes a hard-coded destructive call, DELETE /api/users/1, which could delete a real record if pointed at a non-test environment. In an agent or copy-paste workflow, hard-coded state-changing test actions can be executed against production or shared systems without sufficient safeguards.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
assert_status POST /api/users 201 '{"name":"Test","email":"test@test.com"}'
assert_status GET /api/users 200
assert_json /api/users '.[-1].name' 'Test'
assert_status DELETE /api/users/1 204

# Auth tests
assert_status GET /api/admin 401

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 479)May include surrounding context.

bash
# Basic GET
curl -s https://api.example.com/users | jq .

# With headers
curl -s -H "Authorization: Bearer $TOKEN" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill demonstrates sending bearer tokens and uploading files over HTTP requests without an explicit warning about sensitive data handling, redaction, or endpoint trust. This can normalize unsafe copying of real secrets and files into commands that transmit them to third-party or production endpoints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

curl -s "https://api.example.com/users?page=2&limit=10" | jq .

Show response headers too

curl -si https://api.example.com/users

text

### POST/PUT/PATCH/DELETE

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples include destructive operations such as DELETE requests without any warning to confirm target environment, resource identity, or test-data isolation. In an agent skill, users may copy these commands into real environments, increasing the chance of accidental data deletion or misuse against production systems.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
-d '{"name": "Alice", "email": "alice@example.com"}' | jq .

# PUT (full replace)
curl -s -X PUT https://api.example.com/users/123 \
  -H "Content-Type: application/json" \
  -d '{"name": "Alice Updated", "email": "alice@example.com"}' | jq .

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
-d '{"name": "Alice Updated", "email": "alice@example.com"}' | jq .

# PATCH (partial update)
curl -s -X PATCH https://api.example.com/users/123 \
  -H "Content-Type: application/json" \
  -d '{"name": "Alice V2"}' | jq .

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
-d '{"name": "Alice V2"}' | jq .

# DELETE
curl -s -X DELETE https://api.example.com/users/123

# POST form data
curl -s -X POST https://api.example.com/upload \

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill invokes npx @redocly/cli without pinning an exact version, so execution depends on whatever package version is current at runtime. That creates a supply-chain risk: a compromised or breaking upstream release could be fetched and executed automatically in the user's environment.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 498)May include surrounding context.

Inspect JWT tokens

bash
# Decode JWT payload (no verification)
echo "$TOKEN" | cut -d. -f2 | base64 -d 2>/dev/null | jq .

Static analysis

No suspicious patterns detected.