T08 · Insecure Dependencies
- Location
SKILL.md:48- Finding
Unpinned Runtime Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do what it claims for SubsTracker, but it handles credentials, sessions, and destructive account data with weak scoping and safety controls that users should review before installing.
Install only if you intend agents to manage your SubsTracker instance directly. Use an HTTPS `SUBSTRACKER_URL`, avoid running it from untrusted working directories, protect `~/.substracker-skills` with private permissions, avoid putting passwords or API tokens in command-line flags, and manually confirm any delete, password, webhook, or notification-token changes before allowing the agent to run them.
SKILL.md:48Unpinned Runtime Package Is Automatically Downloaded and Executed
scripts/client.ts:35Credentials and Session Data Can Be Transmitted over Plaintext HTTP
scripts/client.ts:64Persistent Session Cookie Is Written without Explicit Restrictive Permissions
scripts/config.ts:8Administrative Passwords and API Tokens Are Accepted through Command-Line Arguments
The invocation description is extremely broad and triggers on generic phrases about subscriptions, bills, renewals, or notifications, even when the user does not mention SubsTracker. That can cause over-eager activation of a credentialed skill, leading the agent to access a user's local configuration, authenticated session, or remote instance in contexts where the user only wanted general advice or a different service.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
export function loadConfig(): SubsTrackerEnv {
const cwdEnvPath = path.join(process.cwd(), ".substracker-skills", ".env");
const homeEnvPath = path.join(os.homedir(), ".substracker-skills", ".env");
const cwdEnv = loadEnvFile(cwdEnvPath);
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
export function loadConfig(): SubsTrackerEnv {
const cwdEnvPath = path.join(process.cwd(), ".substracker-skills", ".env");
const homeEnvPath = path.join(os.homedir(), ".substracker-skills", ".env");
const cwdEnv = loadEnvFile(cwdEnvPath);
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if (missing.length) {
throw new Error(
`Missing: ${missing.join(", ")}.\n` +
"Set via environment variables or in .substracker-skills/.env file."
);
}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if (missing.length) {
throw new Error(
`Missing: ${missing.join(", ")}.\n` +
"Set via environment variables or in .substracker-skills/.env file."
);
}
The skill documents code execution that reads environment variables and performs authenticated network requests, but it does not declare an explicit tool scope such as allowed tools or permissions. This creates unclear trust boundaries: an agent may invoke a networked, credential-using skill without transparent policy constraints, increasing the chance of unintended secret access or outbound requests.
The documentation instructs the use of .env credentials and numerous secret-bearing config flags such as passwords, bot tokens, webhook URLs, and API keys, but it lacks explicit warnings about sensitive-data handling. In practice this increases the risk that users or agents will expose secrets in command lines, logs, screenshots, shell history, or conversational transcripts.
Using npx -y bun without a pinned version allows execution of whatever package/version is resolved at runtime. If the registry content changes or a malicious package/version is served, the agent could run untrusted code with the same environment and network access as the skill, potentially exposing credentials or altering behavior.
The client persists the raw Set-Cookie header to a file in the user's home directory without setting restrictive file permissions or limiting the stored value to the session cookie only. If another local user, process, backup system, or malware can read that file, the session token may be replayed to impersonate the user against the SubsTracker instance.
The login function sends stored credentials to a remote /api/login endpoint, which is a network operation involving sensitive data. While the code is clear to a developer, there is no confirmation prompt, user-facing notice, or warning comment/docstring near this behavior in the file.
This code collects and transmits multiple sensitive values such as admin credentials, bot tokens, API keys, and webhook endpoints via a POST request. There is no confirmation prompt, user-facing log/print, or explanatory comment/docstring in this file warning that secrets will be sent to the server.
This CLI routes subscriptions delete and payments delete directly to deletion handlers, but the visible help text and command handling here do not provide any confirmation prompt or explicit warning that the operation removes data. Because these are destructive operations, users should receive a clear disclosure before invocation or execution unless that warning is documented elsewhere.
At L23, the function submits the assembled input object to /api/test-notification via a POST request. The input may include user-provided overrides such as bot tokens or webhook-related values derived at L12-L19, but this file provides no confirmation, logging, or user-facing warning that such data will be transmitted.
The del function performs a DELETE request against a payment resource, which is a destructive operation. In this file there is no confirmation prompt, logging, print statement, or explanatory comment/docstring warning that a payment record will be deleted.
This code file exposes a destructive operation via del(id) that issues a DELETE request, but there is no confirmation prompt, logging, print statement, or comment explaining the impact to the user. Under the code-file criteria, destructive or irreversible operations should have some visible disclosure unless the warning is provided elsewhere, which is not evident in this file.
The file embeds a China-specific default currency (CNY) and elsewhere uses Chinese-language example/category strings and note defaults, which collectively indicate a fixed language/locale assumption. Because there is no nearby opt-in, locale selection, or documented regional scope, this can violate the policy against forcing a specific language or locale by default.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal, suspicious.potential_exfiltration