Back to skill

Security audit

Proxy4agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about being a residential-proxy MCP tool, but it promotes anti-bot bypass and includes unpinned npx install commands that would run third-party code with proxy credentials.

Review before installing. Only use this with sites and proxy providers you are authorized to access, avoid sending sensitive URLs or data through the proxy, and prefer a pinned or verified install command such as the reviewed package version rather than the unpinned npx examples.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:32
Finding

Unpinned Third-Party Package Download and Execution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The metadata description explicitly advertises bypassing anti-bot protections and geo-targeting through residential proxies, which meaningfully increases misuse risk. In the context of an agent skill, this normalizes evasion behavior and can facilitate scraping or access patterns that circumvent site defenses and accountability controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The main description again instructs users to route requests through residential devices to bypass anti-bot systems, and this is reinforced by later examples like Cloudflare-protected targets. In context, the skill is not merely describing neutral networking behavior; it is actively steering agent operators toward evasion of defensive mechanisms, which makes harmful use more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs users to launch an MCP server via npx -y bestproxy4agents without pinning an exact package version. This allows a future package update, compromised maintainer account, or dependency hijack to change the code executed at install/runtime, creating a supply-chain execution risk on the user's machine or agent host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This is the same unpinned npx execution pattern repeated in a second setup path, so users following either path may execute whatever package version is current at the time. Because npx fetches and runs code, an attacker who gains control of publishing or dependency resolution could achieve arbitrary code execution in the MCP environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.