Back to skill

Security audit

Supernal Interface

Security checks for vulnerabilities and agentic risk

Overview

This skill is a short, coherent guide for integrating an AI-controllable app framework, with ordinary dependency and state-management cautions but no hidden or destructive behavior found.

Before installing, pin @supernal/interface to a reviewed version, use a lockfile, and review which app functions or readable state you expose to AI assistants, especially if they can mutate data or access sensitive user context.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned External npm Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 11
Vulnerability Type: Unpinned third-party package installation
Risk Level: Medium

bash
npm install @supernal/interface

Technical Analysis

The installation command retrieves @supernal/interface without specifying an exact version. The project contains no lockfile, integrity hash, vendored source, or other mechanism that fixes and verifies the dependency version. Therefore, the code installed by this instruction may change after the Skill has been audited.

npm packages and their transitive dependencies may also execute lifecycle scripts during installation. If the package, a maintainer account, the package registry, or a transitive dependency is compromised, following this instruction could install or execute attacker-controlled code.

Attack Path

  1. An attacker compromises the npm package, a package maintainer account, or a transitive dependency.
  2. The attacker publishes a malicious version that includes harmful runtime behavior or an installation lifecycle script.
  3. A user follows the command in SKILL.md.
  4. npm resolves the unpinned dependency to the attacker-controlled version.
  5. Malicious code executes during installation or later when the application imports and uses the package.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user or build environment running npm. Depending on those privileges, the attacker could access project files and environment variables, steal development credentials, modify build artifacts, compromise generated applications, or move laterally through a CI/CD environment. The scope is limited by the permissions and isolation controls of the installation environment.

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a reviewed exact version rather than relying on the mutable latest release.
  • Commit a package lockfile containing integrity metadata and use npm ci in automated environments.
  • Document the package's authoritative registry and source repository so users can verify its provenance.
  • Audit the package's lifecycle scripts and complete transitive dependency tree before adoption.
  • Use npm ci --ignore-scripts where dependency lifecycle scripts are not required.
  • Enable dependency scanning, registry provenance verification, and automated alerts for compromised or vulnerable releases.
  • Run dependency installation and builds in a least-privileged, isolated environment without unnecessary credentials.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file includes an invocation-style description that says to use the skill when 'adding AI tool decorators, setting up chat adapters, creating AI-callable functions, or integrating CopilotKit.' Those conditions are broad and lack exclusion criteria or a narrow trigger list, which could cause the skill to be invoked across many ordinary AI-integration tasks rather than a clearly bounded context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
// Bind a tool to component state
const [todos, setTodos] = useToolBinding('todos', []);

// Persist state across sessions
const [prefs, setPrefs] = usePersistedState('user-prefs', defaults);

// Chat with app context

Static analysis

No suspicious patterns detected.