Back to skill

Security audit

Daiso CLI

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate lookup purpose, but it repeatedly tells agents to run an unpinned npm CLI, so future unreviewed code could execute on the user's machine.

Review this carefully before installing. The lookup function is coherent and not destructive, but use a pinned reviewed package version such as `daiso@1.0.6`, prefer a sandboxed environment with minimal credentials, and avoid running it from sensitive directories until the dependency source and update process are trusted.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:10
Finding

Execution of an Unpinned Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:10-15, 26-30, 36-46; references/cli-command-map.md:5-56
Vulnerability Type: Unpinned third-party dependency and mutable package execution
Risk Level: High

The Skill instructs the Agent to install and execute the npm package daiso without specifying an exact version, lockfile, or integrity hash.

Vulnerable Code

SKILL.md:10-15:

yaml
install:
  - kind: node
    package: daiso
    bins:
      - daiso

SKILL.md:26-30:

bash
npx daiso health
npx daiso url
npx daiso help

SKILL.md:36-46:

bash
npx daiso products 수납박스 --json
npx daiso stores 강남역 --limit 5 --json
npx daiso inventory 1034604 --keyword 강남역 --json
npx daiso display-location 1034604 04515 --json
npx daiso gs25-products 콜라 --limit 10 --json
npx daiso gs25-stores 강남 --limit 10 --json
npx daiso gs25-inventory 오감자 --storeKeyword 강남 --storeLimit 10 --json
npx daiso seveneleven-products 삼각김밥 --size 10 --json
npx daiso seveneleven-stores "안산 중앙역" --limit 10 --json
npx daiso emart24-products 커피 --pageSize 10 --json
npx daiso lottemart-products 콜라 --storeName 강변점 --area 서울 --json

The same unpinned execution pattern appears throughout references/cli-command-map.md:5-56, including:

bash
npx daiso products 수납박스 --json
npx daiso cu-inventory 과자 --storeKeyword 강남 --json
npx daiso get /api/seveneleven/inventory --keyword 핫식스 --storeKeyword "안산 중앙역" --storeLimit 10 --json
npx daiso get /api/oliveyoung/products --keyword 선크림 --size 10 --json
npx daiso get /api/cgv/timetable --playDate <YYYYMMDD> --theaterCode <theaterCode> --json
npx daiso health

Technical Analysis

A bare invocation such as npx daiso resolves the package through the configured npm registry and may download it when it is not already installed. Because no exact version or verified integrity value is specified, the code executed during future Skill runs can differ from the code that existed when the Skill was reviewed.

The artifa ...[truncated 2344 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed exact version in the installation metadata and every executable example, rather than resolving the latest release:

    yaml
    install:
      - kind: node
        package: daiso@1.0.6
        bins:
          - daiso
    
    bash
    npx --yes daiso@1.0.6 health
    
  2. Do not rely on version pinning alone. Commit a lockfile containing npm integrity hashes and install with a deterministic command such as npm ci.

  3. Review and retain the source corresponding to the pinned release. Where practical, vendor the audited implementation or publish it through a controlled internal registry.

  4. Verify package provenance and integrity before execution. Use npm provenance information, registry signatures where supported, and an approved checksum or integrity policy.

  5. Audit direct and transitive dependencies for known vulnerabilities and unexpected lifecycle scripts. Repeat this review before approving any version update.

  6. Disable package lifecycle scripts with --ignore-scripts when the package remains functional without them. If scripts are required, review each script before permitting execution.

  7. Execute the CLI in a restricted environment with least privilege:

    • Use a dedicated unprivileged account or sandbox.
    • Expose only required files and environment variables.
    • Remove unrelated credentials from the process environment.
    • Restrict outbound network access to documented service endpoints.
    • Avoid running the Skill from privileged or sensitive working directories.
  8. Add an explicit update process requiring source review, integrity verification, testing, and approval before changing the pinned version.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (61)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill installs and runs the daiso package via Node tooling without pinning an exact immutable version. This creates a supply-chain risk: future package updates or a compromised publisher account could cause different code to be fetched and executed than what the skill author reviewed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx daiso without an exact version allows npx to resolve and execute the latest published package at runtime. If the package is updated maliciously or unexpectedly, the skill could execute unreviewed code on the host system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command example invokes npx daiso without version pinning, so the actual code executed may change over time. That exposes users of the skill to remote code execution risk via the npm supply chain if the package is replaced or compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The unpinned npx daiso invocation can fetch and execute whatever version npm resolves at the time of use. That makes the behavior non-deterministic and vulnerable to malicious or unsafe upstream changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This unversioned npx daiso command may execute a different package revision than the skill author intended. In an agent skill context, that increases the chance of silently introducing hostile code into a trusted workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The product search example relies on npx daiso without pinning, enabling runtime retrieval of arbitrary future package versions. Because npx executes code locally, a compromised package could run attacker-controlled code on the system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This store search example executes an unpinned npm package through npx, which is a classic supply-chain exposure. An attacker who compromises the package or publishing pipeline could turn a simple lookup into arbitrary code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The inventory lookup example uses an unversioned npx daiso command, so the executed artifact is not fixed. This weakens reproducibility and opens the door to malicious package substitution or unsafe upstream changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Because this command uses npx daiso without a fixed version, it can execute newly published code without warning. In agent environments, that can convert normal tool usage into supply-chain-driven code execution on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The GS25 product command uses an unpinned package execution path via npx, making the resolved code mutable over time. That creates a meaningful supply-chain vulnerability because the skill encourages repeated execution of whatever npm currently serves.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This unpinned npx daiso store lookup can execute changed upstream code at any time. A malicious or compromised release would run with the same trust as the originally intended CLI.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The GS25 inventory example invokes the CLI through unversioned npx, which can pull arbitrary future code. This is dangerous because users may assume they are running a stable helper when they are actually executing whatever package version npm resolves.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The Seven-Eleven product example uses npx daiso without version pinning, which exposes users to code drift and package compromise. Since npx executes the package locally, a hostile release can directly affect the agent host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This store search example relies on an unpinned npm execution path, so the trusted behavior is not fixed. That is a real supply-chain risk in a skill that explicitly instructs agents to prefer the CLI path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The Emart24 example executes an unversioned package through npx, allowing unreviewed releases to run automatically. This creates a practical supply-chain vector rather than a merely theoretical issue because the command is presented as normal operational guidance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This Lotte Mart example uses npx daiso without an exact version, so package resolution is mutable and remotely controlled by the npm supply chain. If exploited, the host could run attacker-chosen code instead of the intended CLI behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The raw GET example still invokes the CLI via unpinned npx, so it carries the same supply-chain execution risk as the other examples. The fact that it accesses external APIs does not reduce the danger of executing an unreviewed package first.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The fallback example instructs use of npx daiso get without version pinning, so even less common code paths still rely on mutable package resolution. Attackers often benefit from overlooked fallback paths because they receive less scrutiny than primary examples.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The health-check fallback uses an unpinned npx daiso invocation, exposing troubleshooting flows to the same supply-chain risk. Because users may run diagnostics with elevated trust, this can be an especially effective execution vector if the package is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The fallback section references npx and Node.js availability while the skill broadly assumes transient package execution, but without enforcing version pinning. This makes the skill operationally convenient but materially increases the risk of arbitrary code execution from the npm ecosystem.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This line itself is primarily about reporting failures, but it exists in a skill that repeatedly directs use of unpinned npx daiso commands. In context, it reinforces continued use of a mutable remote package during retries, which preserves the same supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The closing recommendation to prefer npx daiso for local shell work again instructs execution of an unpinned npm package. Because this is presented as the preferred path, the skill context makes the supply-chain risk more dangerous by maximizing the chance users will follow it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions explicitly normalize command usage around Korean strings and later require interpreting relative dates using KST. This imposes a specific language/locale behavior in the skill documentation without offering user choice or clearly justifying that the skill is region-specific.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The command map instructs use of npx daiso without pinning a package version, which causes execution of whatever version is currently resolved from the npm registry at runtime. That creates a supply-chain risk: a malicious update, dependency compromise, or typosquat/republication event could make the skill execute attacker-controlled code on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This line relies on npx daiso with no explicit version pin, so execution depends on mutable registry state rather than a reviewed artifact. In an agent skill context, that can turn a simple product lookup into arbitrary code execution if the upstream package or one of its install-time/runtime dependencies is compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.