Back to skill

Security audit

Navil Audit

Security checks for vulnerabilities and agentic risk

Overview

This security-audit skill is mostly purpose-aligned, but it should be reviewed because it installs and runs an unpinned external package against sensitive agent and MCP configuration with broad activation wording.

Install only if you trust the `navil` PyPI package and publisher, and run it with a clearly specified audit target in a constrained environment. Prefer a pinned, hash-verified package version and avoid exposing unrelated credentials, broad home-directory access, or unnecessary network access during scans.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Package Is Installed and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–19
Vulnerability Type: Unpinned external executable dependency
Risk Level: Medium

Vulnerable Code:

yaml
install:
  - id: pip-navil
    kind: pip
    package: navil
    bins: [navil]

Technical Analysis

The skill installs the third-party PyPI package navil without specifying an exact version, package hash, signature, or locked transitive dependency set. It subsequently instructs the Agent to execute commands supplied by that package, including navil scan, navil pentest, and navil report.

The implementation of the dependency is not included in the audited artifact, so its runtime behavior and the claim that penetration testing produces no network traffic cannot be independently verified from the reviewed files. Although checksums.json protects SKILL.md and skill.json, it does not authenticate the external package or its transitive dependencies.

This creates a supply-chain trust boundary in which the code ultimately executed can change after the skill itself has been reviewed. Exploitation would require compromise, replacement, or malicious publication of the dependency or one of its transitive dependencies; no such compromise was established during this audit.

Attack Path

  1. An attacker compromises the navil package, its publishing account, the package distribution process, or a transitive dependency.
  2. The attacker publishes a modified release containing malicious installation or runtime behavior.
  3. Because the skill does not pin an audited version and hash, installation may resolve to the attacker-controlled release.
  4. The skill installation process installs the modified package and exposes its navil executable.
  5. The Agent invokes navil scan, navil pentest, or navil report as directed by the skill.
  6. The malicious dependency executes with the privileges and environmental access of the install ...[truncated 777 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin navil to a specific version that has undergone security review rather than resolving the latest available release.
  2. Require a verified cryptographic hash for the selected distribution, such as through a hash-locked requirements file and pip --require-hashes.
  3. Lock and review the complete transitive dependency graph using a reproducible lockfile.
  4. Verify package provenance through signed releases or trusted-publisher attestations where available.
  5. Prefer vendoring or otherwise making the dependency source available for review with the skill artifact.
  6. Install from an isolated environment using an explicitly configured trusted package index, and disable unexpected fallback indexes to reduce dependency-confusion exposure.
  7. Execute the auditing utility in a sandbox with read-only access to only the required configuration paths, minimal environment variables, no unnecessary credentials, and network access disabled unless a documented function requires it.
  8. Extend integrity metadata to cover the exact external artifacts and dependency versions used at installation time.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description includes many broad trigger phrases such as 'am I safe', 'check for vulnerabilities', and 'what MCP attacks would work against me', which can cause the skill to activate during ordinary security discussions rather than only during explicit audit requests. Because this skill is designed to run scans and penetration-test style actions, overbroad routing increases the chance of unexpected execution, unnecessary access to local configuration, and disclosure of sensitive security posture information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'When to Use This Skill' section broadens activation further with vague phrases like 'security check', 'what attacks would work', and 'before deploying', without requiring explicit consent or defining scope. In context, this is more dangerous because the skill instructs the agent to perform multi-phase auditing and pentest-related actions, so ambiguous invocation can lead to unintended security testing behavior and exposure of environment details.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.