T03 · Remote Payload Retrieval and Execution
- Location
scripts/check-update.mjs:28- Finding
Remote Manifest Can Supply an Arbitrary Update Command for Agent Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill's prompt-generation purpose is coherent, but its updater and installer give remote or user-controlled inputs too much command and persistence authority.
Review this skill before installing, and avoid the one-line npx installer unless it is pinned to a reviewed commit or release. Do not let an agent automatically run update commands printed by the checker; prefer manual installation from a verified source and inspect any target path or environment variable used for installation.
scripts/check-update.mjs:28Remote Manifest Can Supply an Arbitrary Update Command for Agent Execution
scripts/install.mjs:100Shell Command Injection Through Installer Target Path
scripts/install.mjs:100Unpinned Remote Installation Destructively Replaces Existing Skill
The README instructs users to install and execute code directly from a GitHub repository via npx -y github:... without pinning to a specific commit, tag, or verified release. That creates a supply-chain risk: if the repository is compromised or changed later, users may run unexpected code during installation with the same trust as the original skill.
This command executes installer code fetched from GitHub without a pinned version, so the exact code run can change over time. In an agent-skill context, installation often writes into trusted agent skill directories, which increases the blast radius if upstream content is modified maliciously.
The --codex install example still relies on npx -y github:... without immutable version pinning. A compromised upstream repository or account could cause arbitrary code execution on install and persistence inside ~/.codex/skills.
The --claude variant has the same unpinned remote execution issue: it fetches and runs mutable GitHub content at install time. Because it targets a privileged agent skill path, successful exploitation could persist attacker-controlled behavior in future agent sessions.
This custom --target=/path install form still executes an unpinned GitHub installer, preserving the same supply-chain risk. The ability to choose arbitrary target directories may further increase impact if a user points installation at sensitive or broadly trusted locations.
The 'Agent Auto-Install Prompt' embeds the same unpinned npx -y github:... command, which is especially risky because it is framed as automation-ready text for an agent to execute. This lowers human review and increases the chance that mutable upstream code is run automatically.
The compatibility section repeats the unpinned GitHub npx install pattern for Codex, exposing users to the same mutable-source execution risk. While this is documentation rather than code in the repository, it is still actionable guidance that can directly lead to compromise.
This Claude Code compatibility example instructs users to execute remote installer code from an unpinned GitHub source. Since it modifies a trusted skill directory, any malicious upstream change could create persistence and affect later agent behavior.
The OpenCode example again uses npx -y github:... without version pinning, creating a repeat supply-chain exposure. The surrounding skill context makes this more dangerous because the install target is an agent skill directory that may be trusted and invoked later without re-review.
The generic custom-target install example still fetches and runs mutable remote code from GitHub. In this context, the skill is designed for agent integration, so compromise could extend beyond one command and influence future automated workflows.
The README instructs users to execute code directly from a GitHub repository via npx -y github:... without pinning to a specific commit, tag, or release. That means future changes to the repository or a repository compromise could cause users to run unexpected code during installation, creating a supply-chain execution risk.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
安装脚本会自动检测 Codex(~/.codex/skills)和 Claude Code(~/.claude/skills)。指定 Agent 或自定义目录:
npx -y github:HiAPIAI/hiapi-video-prompt-generator-skill --codex # 只装到 ~/.codex/skills
npx -y github:HiAPIAI/hiapi-video-prompt-generator-skill --claude # 只装到 ~/.claude/skills
npx -y github:HiAPIAI/hiapi-video-prompt-generator-skill --target=/path # 自定义目录
AGENT_SKILLS_DIR=/path npx -y github:HiAPIAI/hiapi-video-prompt-generator-skill -y
This line recommends running an unpinned GitHub-backed npx install command. Because the fetched installer can change over time, a malicious update or account/repository compromise could result in arbitrary code execution on the user's machine.
The command executes installer code from GitHub without version pinning, so users are trusting the current state of the remote repository at execution time. In an agent-skill ecosystem, that increases exposure because automated systems may follow README installation guidance without human review.
Using npx -y github:... --target=/path still pulls and runs code from an unpinned GitHub source. If the upstream repository changes or is compromised, the installation behavior may change silently and execute attacker-controlled code in the local environment.
Setting AGENT_SKILLS_DIR does not reduce the core risk: the npx -y github:... command still executes unpinned remote code. This creates a supply-chain risk where installation instructions can become an execution vector if the repository or maintainer is compromised.
The auto-install prompt tells an agent to run an unpinned GitHub npx command. This is especially risky in an agent context because users may paste it into tools that execute instructions with limited scrutiny, turning README text into an indirect remote-code-execution path.
The compatibility section repeats the unpinned npx -y github:... install pattern. Repetition increases the likelihood of unsafe adoption and normalizes execution of mutable remote code for installation.
This install command again relies on a mutable GitHub source for npx, allowing silent behavioral drift or compromise-driven code execution. The risk remains supply-chain related even if the current repository is benign.
The OpenCode example uses the same unpinned remote execution pattern. In automation-heavy environments, such instructions can be consumed verbatim, magnifying the chance that compromised upstream code is executed across multiple developer machines.
The Cursor/other-agent install example still executes unpinned GitHub code. The skill context makes this somewhat more dangerous because the project explicitly targets agent tooling, where installation may be semi-automated and trusted more readily than ordinary shell snippets.
The skill instructs the agent to run a local command and references an environment variable (HIAPI_SKIP_UPDATE_CHECK=1), but the skill declares no explicit tool scope or permissions. That creates an authority gap: an agent may execute shell access or inspect environment-dependent behavior without a clear, least-privilege declaration, which can enable unintended command execution or exposure of sensitive local context if the runtime permits it.
The skill enables implicit invocation and uses broad default invocation wording, which can cause the agent to trigger this skill in situations where the user did not clearly request it. In a prompt-generation skill, unintended activation can introduce unnecessary data flow into the skill and produce outputs that appear authoritative or source-grounded when the user did not intend to invoke this capability.
The script accepts an update command from a remotely fetched manifest and falls back to an unpinned npx -y github:... source, which can cause users or automation to execute code that is not version-locked. If the GitHub source, manifest, or repository ref is changed or compromised, the suggested update path can lead to arbitrary code execution during installation.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Detected: suspicious.dangerous_exec