T08 · Insecure Dependencies
- Location
README.md:42- Finding
Unpinned Third-Party Package Execution During Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This contact-memory skill is purpose-related but needs Review because it stores sensitive relationship data in plaintext, mandates external lookups, silently mutates action history, and uses unverified mutable update/install paths.
Install only if you are comfortable keeping sensitive contact and relationship notes as local plaintext files. Avoid storing secrets or highly sensitive third-party details, keep the directory out of shared repos and sync folders, require confirmation before web searches or image downloads, and do not use the mutable GitHub-main update path or unpinned npx install without reviewing and pinning the exact version.
README.md:42Unpinned Third-Party Package Execution During Installation
README.md:35Mutable Remote Skill Payload Retrieved Without Integrity Verification
SKILL.md:3Sensitive Personal and Contact Data Stored in Plaintext Markdown
SKILL.md:54Automatic Disclosure of Person Names and Context to External Search Providers
SKILL.md:32Silent Destructive Cleanup Triggered by Reading the Actions File
The skill presents itself as a local contacts tool, but repeatedly requires outbound web searches and remote fetches during normal operation. This expands the trust boundary, can disclose user queries about real people to third parties, and creates a mismatch between user expectations and actual network behavior.
The skill instructs silent cleanup and deletion of user data, including automatic removal and status changes, without notice or confirmation. Silent mutation of personal records can destroy context, reduce auditability, and cause loss of information the user expected to retain.
The skill instructs storing highly sensitive personal details—such as debts, conflicts, health issues, family information, and topics to avoid—in plain markdown for later use. Centralizing intimate third-party data in human-readable local files increases exposure risk if the workspace is accessed, synced, indexed, or surfaced by other tools.
The recurring 'Peeps: check' behavior directs the agent to proactively inspect random personal files and surface details in DM or other channels. In a dataset that explicitly includes private notes, family details, health issues, and sensitive topics, proactive resurfacing materially increases the chance of privacy leakage and context-inappropriate disclosure.
The skill explicitly instructs updating itself by fetching a remote SKILL.md and replacing the local file, which is direct self-modification. Self-modifying behavior is dangerous because it bypasses stable review boundaries and allows remote content to redefine future instructions and capabilities.
To update this skill to the latest version, fetch the new SKILL.md from GitHub and replace this file:
https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md
This skill handles highly sensitive personal contact and relationship data, but the introductory description does not clearly foreground the privacy implications and local plaintext storage risks. Users may store sensitive notes, affiliations, and interpersonal context without realizing those files may be readable by other local processes, backups, sync tools, or shared accounts.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Mandating web searches for people before asking follow-up questions sends personal names and context to external services without a clear privacy warning or consent step. Because this skill handles relationship data, even a simple lookup may reveal sensitive associations or intentions.
The instruction to fetch headshots and store them locally introduces collection of third-party personal data that is not necessary for basic contact remembrance or introductions. It increases privacy risk, copyright/licensing risk, and may normalize saving biometric-adjacent imagery without clear consent or need.
Fetching external images into local assets without a strong consent and provenance flow can import unnecessary personal data and untrusted content. The lack of a clear warning is especially problematic in a skill centered on private contacts and personal relationship notes.
Suggesting cron-based periodic execution gives the skill a standing background presence unrelated to a simple on-demand contacts utility. This increases the chance of repeated unsolicited access to personal files and proactive disclosure of sensitive relationship data.
The self-update instruction pulls remote content from GitHub and replaces the skill file, introducing an administrative network capability outside the skill's stated purpose. This creates a supply-chain and integrity risk because future behavior can change via remote content without review.
The self-update flow instructs replacing the skill from a remote URL without a safety review or verification step. This can silently alter future behavior and permissions, making the skill vulnerable to supply-chain compromise or unsafe upstream changes.
No suspicious patterns detected.