T08 · Insecure Dependencies
- Location
README.md:33- Finding
Unpinned Remote Skill Installation and Update Channels
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent personal place-notes helper, but it deserves Review because it recommends mutable self-updates, recurring checks, plaintext API-key storage, and external lookups involving personal location interests.
Review before installing. Use it only if you are comfortable storing personal place history in workspace files and sending place queries to web services when enrichment is used. Do not enable the cron/heartbeat reminder unless you want recurring access to those notes. If using Google Places, restrict the API key, keep nooksconfig.yml out of git, and prefer pinned or reviewed updates instead of replacing the skill from a mutable main-branch URL.
README.md:33Unpinned Remote Skill Installation and Update Channels
README.md:87Plaintext API Key Storage with an Unsupported Git-Exclusion Assurance
SKILL.md:137Unnecessary Recurring Execution Through Heartbeat or Cron
The skill explicitly instructs the agent to fetch a remote SKILL.md from GitHub and replace the current file, which is a self-modification pathway. This is dangerous because it allows remote content to alter future agent behavior, potentially introducing malicious instructions or silently broadening permissions if the upstream source is compromised or changed.
To update this skill to the latest version, fetch the new SKILL.md from GitHub and replace this file:
https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The invocation cues are broad enough to match ordinary conversation about places, eating, meeting, or working in a city. That increases the chance the agent activates this skill unexpectedly and performs note-taking or lookups without the user clearly intending to use the skill.
The skill instructs the agent to create directories and files on first use with no requirement to notify the user before modifying the workspace. Silent file creation and updates can violate user expectations, create persistence unexpectedly, and make it harder to audit what data the agent stored.
The skill expands from local note management into external web search, Google Places API calls, and image fetching without requiring an explicit user opt-in at the moment of use. This can cause unintended disclosure of user interests, locations, or place names to third-party services and increases the skill's attack surface beyond its stated local-storage purpose.
The skill directs external searches, API calls, and image lookups but does not require a user-facing privacy warning when those actions occur. Because place names, neighborhoods, and preferences can reveal sensitive personal context, sending them to third parties without notice creates a privacy risk.
The core behavior encourages activation on passing mentions of places and observations, which can cause the agent to infer consent to create or update records from casual conversation. In a personal-memory skill, this is risky because it may capture sensitive habits, meetings, or location preferences without clear user approval.
The heartbeat/cron guidance introduces recurring autonomous behavior unrelated to the core task of saving and retrieving place notes. Periodic unsolicited checks can lead to surprise background activity, repeated file scanning, and increased opportunities for privacy-invasive prompts or workflow disruption.
The README says the skill "searches the web first" to pre-fill place information, which implies sending the user's requested place/query to external services. It describes the feature as convenience functionality but does not clearly warn that user-provided place information may be transmitted to third-party services during save operations.
The README explains that the agent will "automatically fetch" Maps links using the Google Places API, but the warning focuses on API-key storage rather than disclosure that user-entered place queries are shared with Google. For a skill storing personal place history, this external transmission has privacy implications that should be explicitly disclosed.
The saving instructions explicitly say not to ask the human to install a key or paste a share link when a maps link is unavailable. Later, the document includes a full setup flow for configuring a Google Places API key, which contradicts that earlier directive at the documentation level.
No suspicious patterns detected.