Back to skill

Security audit

Skill Reviewer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent skill-review checklist, but it includes under-scoped instructions that could lead users to execute untrusted or mutable remote code during reviews.

Use this skill as a static checklist, but do not run npx @latest installers or commands copied from unknown skills on a normal workstation. Pin and verify any installer, and test untrusted skill commands only in a disposable sandbox without secrets, host mounts, credential agents, or broad network access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:378
Finding

Execution of an Unpinned Registry Package Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 378
Vulnerability Type: Unpinned third-party package execution
Risk Level: High

Vulnerable Code Snippet:

bash
# Install the skill
npx molthub@latest install skill-name

Technical Analysis

The documented workflow uses npx to retrieve and execute the mutable latest release of the molthub package. No exact version, integrity hash, lockfile, provenance check, or trusted package-source validation is required.

Because the latest tag can be reassigned after this skill has been reviewed, the code ultimately executed may differ from the code that was originally assessed. Package installation hooks and the package executable run with the permissions of the user invoking npx.

This is a supply-chain weakness. Exploitation would require compromise of the package, its publisher account, the registry distribution process, or another mechanism capable of causing an unsafe release to resolve through the specified package name.

Attack Path

  1. An attacker compromises the package publisher, registry entry, or release pipeline for molthub.
  2. The attacker publishes a malicious release and assigns it to the latest distribution tag.
  3. A reviewer follows the documented workflow and runs npx molthub@latest install skill-name.
  4. npx downloads and executes the attacker-controlled release.
  5. The malicious package executes with the invoking user's permissions and can access resources available to that account.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the privileges of the user running the review workflow. The accessible scope may include project files, user-owned files, environment variables, developer credentials, package-manager credentials, and network resources available to that account.

This instruction does not itself request elevated privileges, so direct root or administrator ...[truncated 146 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable latest tag with an explicitly audited package version, such as molthub@X.Y.Z.
  • Verify package ownership, source repository, release provenance, and signatures before execution.
  • Use lockfiles and registry-supported integrity metadata where applicable.
  • Configure the package manager to use a trusted registry rather than an uncontrolled mirror.
  • Review package lifecycle scripts before allowing installation or execution.
  • Run the installation in a disposable, non-root sandbox without secrets or host filesystem mounts.
  • Disable outbound networking during execution unless network access is essential.
  • Document the expected package checksum or other verifiable release identity and provide a process for securely updating it.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:365
Finding

Unsafe Execution of Commands Taken From Potentially Untrusted Skills

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 365-367 and line 387
Vulnerability Type: Insufficient isolation when testing untrusted commands
Risk Level: High

Vulnerable Code Snippets:

bash
# 6. Test commands (sample 3-5 from the skill)
# Run them in a clean shell to verify they work

# 7. Run the scorecard mentally or in a file
markdown
- Test 3-5 commands from the skill in a clean environment. If more than one fails, the skill wasn't tested before publishing.

Technical Analysis

The review process directs an agent to execute commands copied from a skill that may have been downloaded from an untrusted registry. It only calls for a “clean shell” or “clean environment” and does not define an enforceable security boundary.

A clean shell does not prevent commands from reading user files, environment variables, SSH or cloud credentials, modifying the filesystem, opening network connections, spawning background processes, or downloading secondary payloads. The workflow also does not require static inspection before execution, non-root privileges, network isolation, resource limits, or a disposable filesystem.

An attacker can disguise harmful behavior as an ordinary setup or verification command in a skill under review. If a reviewer follows this testing guidance on a normal workstation, the command executes with the reviewer's effective permissions.

Attack Path

  1. An attacker publishes or supplies a skill containing a malicious command presented as a legitimate example.
  2. A reviewer installs or opens that skill and follows the skill-reviewer workflow.
  3. The reviewer selects the malicious command as one of the recommended three to five samples.
  4. The command runs in a clean shell that still retains access to the host filesystem, user identity, credentials, and network.
  5. The command reads or modifies accessible resources and may retrieve and execute additional c ...[truncated 851 chars]
Remediation
View remediation

Remediation Suggestions

  • Require static review of every command before any dynamic testing.
  • Never execute examples from an untrusted skill directly on a developer workstation.
  • Use a disposable container or virtual machine with:
    • A non-root user
    • No host filesystem mounts
    • No inherited secrets or sensitive environment variables
    • No SSH agent, cloud credential, or container-engine socket access
    • A read-only base filesystem and disposable writable layer
    • CPU, memory, process, and execution-time limits
    • Outbound networking disabled by default
  • Permit network access only through an explicit allowlist when a test genuinely requires it.
  • Inspect commands for shell substitution, encoded payloads, remote downloads, destructive operations, persistence mechanisms, and credential access before execution.
  • Capture filesystem and network activity during tests and destroy the environment after each sample.
  • Replace the ambiguous phrase “clean environment” with a precise sandboxing procedure and mandatory security controls.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description says to use the skill when 'reviewing someone else's skill, scoring skill quality, identifying defects in skill content, or improving an existing skill,' which is expansive and lacks exclusion boundaries. Although the file focuses on SKILL.md review, it does not provide negative examples or tighter trigger constraints to prevent over-invocation for generic review or editing requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 350)May include surrounding context.

bash
# 1. Validate frontmatter
head -20 skills/my-skill/SKILL.md
# Visually confirm YAML is valid

# 2. Count code blocks

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 354)May include surrounding context.

bash
# 1. Validate frontmatter
head -20 skills/my-skill/SKILL.md
# Visually confirm YAML is valid

# 2. Count code blocks

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 358)May include surrounding context.

bash
# 1. Validate frontmatter
head -20 skills/my-skill/SKILL.md
# Visually confirm YAML is valid

# 2. Count code blocks

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 361)May include surrounding context.

bash
# 1. Validate frontmatter
head -20 skills/my-skill/SKILL.md
# Visually confirm YAML is valid

# 2. Count code blocks

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The workflow instructs users to run npx molthub@latest install skill-name, which executes a remote package at the moving latest tag. That creates a supply-chain risk: a compromised publisher account or malicious update could execute attacker-controlled code on the reviewer’s system at review time.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 381)May include surrounding context.

md
npx molthub@latest install skill-name

# Read it
cat skills/skill-name/SKILL.md

# Run the quick review template
# If score < 25, consider uninstalling and finding an alternative

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This section treats the presence of 'Use when...' trigger phrases as a quality criterion, but does not require those triggers to be specific enough to avoid collisions with ordinary requests. Because the skill is itself a reviewer of other skills, this recommendation can propagate vague activation patterns into generated or improved skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.