Back to skill

Security audit

Pages: Books that stay with you.

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent local reading-log helper, but its unverified self-update instructions and recurring cron/heartbeat suggestion create review-worthy risk.

Review this skill before installing if you keep sensitive reading notes. Prefer a pinned, reviewed version instead of the README curl/npx examples, avoid replacing SKILL.md directly from the main branch, and only enable web lookups, Peeps/Haah integrations, or cron/HEARTBEAT checks after explicit approval.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:38
Finding

Unpinned and Unverified Skill Installation and Update Sources

Content
View full analysis

Vulnerability Details

File Location: README.md:38-52; SKILL.md:196-200
Vulnerability Type: Supply-chain exposure through mutable and unverified external sources
Risk Level: Medium

Vulnerable Code

README.md:38-52:

bash
mkdir -p ~/.claude/skills/pages
curl -o ~/.claude/skills/pages/SKILL.md https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md
bash
npx skills add haah-ing/pages-skill
bash
hermes skills install pages

SKILL.md:196-200:

markdown
## Updating

To update this skill to the latest version, fetch the new SKILL.md from GitHub and replace this file:

https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md

text

Technical Analysis

The documented installation and update processes obtain content from sources whose exact revisions are not pinned or cryptographically verified. The direct download uses the mutable GitHub main branch rather than an immutable commit or signed release. The npx and Hermes commands similarly omit explicit, reviewed versions and integrity-verification requirements.

Although the curl command does not pipe downloaded data directly to a shell, it writes the remote file into the Agent's active skill directory. The resulting SKILL.md is subsequently treated as trusted Agent instructions. Consequently, a future upstream change or compromise can alter the effective behavior after the version reviewed in this audit.

This is a supply-chain weakness rather than evidence that the current upstream content is malicious. No malicious embedded script or direct remote shell-execution command was identified in the audited files.

Attack Path

  1. An attacker compromises an upstream repository, package, publication account, distribution service, or maintainer credential.
  2. The attacker modifies the mutable main branch or publishes a compromised package version.
  3. A user follows th ...[truncated 1215 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin direct downloads to an immutable, reviewed Git commit or versioned release instead of main.
  2. Publish SHA-256 checksums or cryptographic signatures for every release and require users to verify them before installation.
  3. Download updates to a temporary review location rather than replacing the active SKILL.md immediately.
  4. Compare the downloaded file with the currently installed version and require explicit user approval before activation.
  5. Pin exact package versions in npx and Hermes installation examples where supported.
  6. Document the expected package publisher, repository identity, release version, and integrity value to reduce dependency-confusion and account-impersonation risks.
  7. Prefer signed release artifacts with a documented key-verification procedure.
  8. Avoid automatic updates from mutable branches and preserve a known-good version for rollback.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The skill explicitly instructs updating itself by fetching a remote file and replacing the local SKILL.md, which is a direct self-modification capability. This is dangerous because it allows externally sourced instructions to overwrite trusted local behavior, creating a clear path for supply-chain compromise, privilege expansion, or persistence of malicious logic.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

Updating

To update this skill to the latest version, fetch the new SKILL.md from GitHub and replace this file:

text
https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

Claude Code

bash
mkdir -p ~/.claude/skills/pages
curl -o ~/.claude/skills/pages/SKILL.md https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

Claude Code

bash
mkdir -p ~/.claude/skills/pages
curl -o ~/.claude/skills/pages/SKILL.md https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

bash
mkdir -p ~/.claude/skills/pages
curl -o ~/.claude/skills/pages/SKILL.md https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md

Other agents

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

bash
mkdir -p ~/.claude/skills/pages
curl -o ~/.claude/skills/pages/SKILL.md https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md

Other agents

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

bash
mkdir -p ~/.claude/skills/pages
curl -o ~/.claude/skills/pages/SKILL.md https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md

Other agents

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx skills add haah-ing/pages-skill without pinning a version or commit. That makes installation dependent on whatever package version is current at execution time, which creates supply-chain risk if the package is later compromised or a breaking/malicious release is published.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs web searching for book metadata and also includes remote self-update behavior, extending beyond a local reading-log role into networked actions. This is dangerous because it can leak user interests or workspace context to external services and normalize fetching untrusted remote content into the local environment without explicit consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes web search and external fetch behavior without a clear warning that network use may expose the user's interests, prompts, or metadata to third parties. In a personal reading log context, that omission is significant because reading habits can be sensitive and users may reasonably expect local-only handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to surface relevant reads contextually when conversation touches a theme creates a broad activation trigger that can cause the skill to engage during ordinary conversation without a clear user request. This increases the chance of unintended file searches, disclosure of private reading history, or distracting autonomous behavior outside the user's immediate intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs modifying HEARTBEAT.md or creating cron jobs, which changes unrelated system or workspace automation outside the narrow purpose of maintaining reading notes. This is risky because it expands persistence and execution surface, potentially causing unintended recurring behavior or unauthorized modification of files the user did not ask to change.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The update instructions tell the agent to fetch a remote SKILL.md from GitHub and replace the current file, but do not warn the user that this is a full replacement of local executable instructions from the network. This creates a supply-chain style risk where compromised upstream content or a mistaken fetch could alter future behavior of the skill in unsafe ways.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown describes creating a searchable personal intelligence layer, storing notes, quotes, and who recommended books, which can include sensitive personal preferences and relationship data. There is no accompanying warning about privacy implications, local file exposure, or being mindful about what personal content is recorded.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description implies a narrowly scoped structure of one markdown file per book in pages/. The actual documented behavior uses a richer filesystem layout including mind/pages/pagesconfig.yml, status subfolders, optional image links into ../assets, and optional edits to Peeps files, which goes beyond the simple description presented in the manifest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes a skill for maintaining and surfacing personal reading notes. The Haah integration extends the skill into outreach/recommendation dispatch to external circles, which is a separate social or messaging capability not inherent to managing local book files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.