Back to skill

Security audit

artifacts-builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent frontend artifact builder, with expected project setup and bundling behavior, but users should know it installs packages and may mutate local build files.

Install only if you are comfortable with it creating a React project, installing many npm dependencies, and potentially installing pnpm globally. Run the bundling script from the intended project root and avoid using it where dist or bundle.html contain important non-build files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs state-changing actions in the user's project environment without meaningful consent or safety controls: it installs new dev dependencies, creates a .parcelrc file, and deletes dist and bundle.html. In an agent-driven workflow, these side effects can unexpectedly modify a repository, affect lockfiles/build behavior, or remove user data, which is risky even if the script's apparent purpose is legitimate bundling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script automatically runs npm install -g pnpm when pnpm is missing, which changes the user's global environment without explicit consent. This is risky because global package installation requires elevated trust, can affect other projects or shell environments, and may surprise users running an initialization script they expect to be local-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.