T08 · Insecure Dependencies
- Location
SKILL.md:72- Finding
Mutable npm Package Is Downloaded and Executed at Runtime
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a disclosed Brave Search integration, but it also enables unpinned runtime CLI execution and autonomous wallet-funded credit purchases that exceed ordinary search needs.
Review before installing. Use this only if you trust the Vincent CLI and service, pin or preinstall a reviewed CLI version, keep search credentials separate from payment credentials, and do not expose a wallet or enable auto-top-up unless strict external spend limits and human approval are enforced.
SKILL.md:72Mutable npm Package Is Downloaded and Executed at Runtime
SKILL.md:184Search Skill Enables Autonomous Cryptocurrency Spending Beyond Necessary Privileges
Autonomous wallet-based credit purchase is not necessary to perform web search and creates a direct path from benign user intent to financial execution. In context, this is especially dangerous because the skill is agent-oriented and encourages unattended operation, so a prompt-triggered or compromised agent could spend cryptocurrency without meaningful user review.
The trigger phrases are broad and generic, making it more likely the skill activates in contexts where the user did not intend to invoke this particular integration. Because the skill includes secret creation and payment-related capabilities, accidental activation is more dangerous than for a narrow read-only skill.
The documentation claims human oversight as part of the security model, but later sections explicitly enable autonomous credit purchases without human intervention. This inconsistency can mislead reviewers and users about actual risk, causing the skill to be deployed under weaker safeguards than its behavior warrants.
The skill metadata permits execution of Bash(npx:@vincentai/cli*), and this occurrence documents invoking the package without a pinned immutable version. Unpinned npx execution can pull whatever package version is current at runtime, creating a supply-chain risk where a compromised or malicious upstream release gains code execution in the agent environment.
This command uses npx @vincentai/cli in a way that may resolve a remote package version at execution time rather than a reviewed local artifact. In an agent skill, that means the trust boundary extends to the npm registry and package publisher account, enabling arbitrary code execution if the dependency is ever hijacked.
The documented use of npx @vincentai/cli without an immutable pin creates a runtime package substitution risk. Because the skill is intended for autonomous operation, any compromise of the package distribution channel could directly affect unattended agents and any secrets or wallets available to them.
This occurrence continues the pattern of unpinned npx execution for a privileged CLI that manages secrets and API access. The combination of secret management and dynamic package resolution materially raises the impact of supply-chain compromise beyond a normal documentation issue.
This command invokes the same unpinned external CLI in the context of key recovery (secret relink), which could expose or overwrite authentication state if the package is compromised. Since relinking re-establishes access, an attacker-controlled package could capture tokens or mint unauthorized access paths.
The skill is presented as a web/news search capability, but the documentation expands its scope into credit purchasing, payment orchestration, and wallet interactions. This broadening violates least privilege and increases the blast radius: a skill invoked for information retrieval can now spend funds and interact with payment infrastructure.
The skill describes autonomous wallet-based credit purchasing without a prominent user warning about spending, wallet usage, or transaction signing risk. In an autonomous agent context, lack of conspicuous warning materially increases the chance of users enabling a capability that can move funds without understanding the consequences.
The balance-check command again relies on an unpinned npm package executed via npx, preserving the same supply-chain code execution risk. In this skill, the CLI is trusted to access account and billing state, so compromise could leak financial or credential information.
Here the unpinned npx package is used for credits add, which interacts with wallet/payment flows. A compromised upstream package could trigger fraudulent payment behavior, redirect funds, exfiltrate wallet material, or manipulate transaction details, making the financial impact especially severe.
Card checkout initiation is outside the stated search purpose and enables the skill to generate payment flows for the user. Even if payment entry occurs through Stripe, a search skill should not be able to trigger billing links by default because it expands the capability from retrieval to monetization and phishing-adjacent behaviors.
This checkout command also uses dynamic npx execution, extending supply-chain risk into billing and payment initiation. Even if card entry happens elsewhere, a compromised CLI could generate phishing checkout URLs or misdirect the user to attacker-controlled payment pages.
The auto-replenish example embeds unpinned npx usage in a scripted flow that may run automatically when credit is low. That combines supply-chain risk with unattended financial actions, so a malicious package update could repeatedly execute unauthorized top-ups or other arbitrary commands without immediate human review.
This auto-top-up invocation uses unpinned npx for a payment action in a conditional automation block. Because it is designed to execute when balance thresholds are crossed, a compromised package could silently escalate from search functionality into unauthorized recurring spending or broader host compromise.
No suspicious patterns detected.