Back to skill

Security audit

Scanner

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent document-scanning helper, but it asks users to run unpinned npm tooling and load mutable remote browser scripts that could process sensitive document images.

Review the dependency steps before installing. Prefer pinned package versions, a lockfile-managed local install, immutable script URLs or vendored reviewed copies, and avoid processing sensitive identity, financial, legal, medical, or business documents through pages that load mutable third-party scripts.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:58
Finding

Mutable Remote JavaScript Is Retrieved and Executed Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis The recommended workflow executes JavaScript directly from external hosts without Subresource Integrity verification. In particular, the `jscanify` URL references the mutable `master` branch rather than an immutable release or commit. Consequently, the effective code executed by users can change after this skill has been reviewed. Although the OpenCV URL specifies a version path, it is still remotely hosted and lacks an integrity hash. The security of the resulting page therefore depends on the upstream repositories, maintainers, hosting services, and delivery infrastructure remaining trustworthy. This is a remote payload execution channel rather than evidence that the current upstream files are malicious. ### Attack Path 1. An attacker compromises an upstream repository, maintainer account, CDN account, or relevant delivery infrastructure. 2. The attacker modifies the file served from the mutable `jscanify@master` location, or otherwise alters a remotely served script. 3. A user follows the skill instructions and opens the local document-scanning page. 4. The browser downloads and executes the modified JavaScript in the page's origin. 5. When the user selects or processes a document image, the malicious script can access data made available to the page and transmit it to an attacker-controlled endpoint. ### Impact Assessment Malicious remote JavaScript would execute with the privileges of the browser page. It could read document images explicitly selected or exposed by the user, alter scan results, falsify displayed output, and send accessible document content or meta ...[truncated 313 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:45
Finding

Unpinned npm and npx Dependencies Create Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
` and `serve@`. 2. Add dependencies to a project manifest and commit the generated lockfile. 3. Use `npm ci` for reproducible installation rather than resolving current releases with `npm install`. 4. Invoke the locally installed, pinned server through a package script instead of allowing `npx` to fetch an unspecified release. 5. Where `npx` is unavoidable, specify an exact package version and prevent interactive substitution. 6. Review transitive dependencies and npm lifecycle scripts before installation. 7. Run dependency tooling as an unprivileged user in an isolated project directory, never with elevated privileges. 8. Use registry integrity checks, dependency scanning, and controlled update procedures. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs users to run npx serve . without pinning a specific package version. npx may fetch the latest published package at execution time, so a compromised upstream release, typo-squat, or unexpected breaking update could result in unreviewed code being executed on the user's machine. In this skill's context, the command is presented as a routine preview step, which increases the chance that users will run it directly with little scrutiny.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.