Back to skill

Security audit

Node Auto Debugger

Security checks for vulnerabilities and agentic risk

Overview

This debugger is mostly a straightforward project scanner, but its optional build mode can run a target project's npm build script with the user's permissions.

Install only if you are comfortable running a local scanner over the target project's source. Do not use --build on third-party or untrusted repositories unless you run it in a disposable sandbox with secrets and network access removed, because the target project's build script can execute arbitrary commands. Expect the tool to write or overwrite AUTO-DEBUG-REPORT.md in the scanned project.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auto-debug.js:226
Finding

Arbitrary Project-Script Execution During Optional Build Verification

Content
View full analysis

Vulnerability Details

File Location: scripts/auto-debug.js, lines 226–235
Vulnerability Type: Execution of untrusted project build scripts without isolation
Risk Level: High

Vulnerable Code

js
const pkg = JSON.parse(fs.readFileSync(pkgPath, 'utf8'));
if (!pkg.scripts?.build) return;

this.log('Running build check...');
const result = spawnSync('npm', ['run', 'build'], {
  cwd: this.projectDir,
  encoding: 'utf8',
  timeout: 120000,
  stdio: ['pipe', 'pipe', 'pipe']
});

Technical Analysis

When the documented --build option is enabled, the scanner reads the target project's package.json and invokes npm run build. The build command itself is defined by the scanned project and must therefore be treated as untrusted.

Although spawnSync uses a fixed executable and argument array, preventing direct shell injection through projectDir, it deliberately delegates execution to an attacker-controlled npm script. That script can contain arbitrary commands. The child process is not sandboxed, assigned reduced privileges, restricted to an allowlisted filesystem, or denied network access. The 120-second timeout only limits execution duration; it does not constrain the operations performed before termination.

Optional build verification is part of the Skill's declared functionality, but unrestricted execution with the invoking user's full permissions exceeds the minimum privileges required for static source analysis. No direct HTTP client, socket, upload, or other network-exfiltration implementation was found in the reviewed Skill itself. However, a malicious build script can independently establish network connections and exfiltrate information.

Attack Path

  1. An attacker creates or modifies a scanned Node.js project.

  2. The attacker defines a malicious scripts.build entry in that project's package.json.

  3. A user or Agent runs:

    bash
    node scripts/auto-debug.js /path/to/untrusted-project --build
    
  4. The s ...[truncated 1326 chars]

Remediation
View remediation

Remediation Suggestions

  1. Keep static analysis as the default and clearly classify build verification as execution of untrusted project code.
  2. Before execution, display the exact scripts.build value and require explicit, informed user approval rather than relying only on the presence of --build.
  3. Execute builds in a disposable sandbox or container configured with:
    • A non-root, dedicated user.
    • A read-only source mount where feasible.
    • A separate writable build-output directory.
    • No access to the host home directory, SSH agent, cloud metadata service, or credential stores.
    • A minimal, scrubbed environment without tokens or secrets.
    • Network access disabled by default or restricted to an explicit allowlist.
    • CPU, memory, process-count, file-size, and execution-time limits.
  4. Avoid exposing sensitive host paths, sockets, or environment variables to the build process.
  5. Warn that npm lifecycle hooks and build-time dependencies can execute code, even when the visible build script appears benign.
  6. If secure isolation is unavailable, omit automated build execution and report the build command for the user to run manually in an appropriately isolated environment.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
node scripts/auto-debug.js <project-dir>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/auto-debug.js (reported line 56)May include surrounding context.

js
for (const file of backendFiles) {
      const content = fs.readFileSync(file, 'utf8');
      if (content.includes('process.env') && content.includes('.env')) continue;
      const lines = content.split('\n');
      for (let i = 0; i < lines.length; i++) {
        const line = lines[i];

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The optional build check executes npm run build inside an untrusted project, which runs arbitrary package scripts and build tooling defined by that project. In a security-audit context, this is dangerous because scanning a repository can unexpectedly trigger attacker-controlled code execution on the analyst's machine or CI runner.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The tool can run project-controlled build commands without an explicit safety warning at the point of use. Because npm build scripts are arbitrary code, this creates a significant trust-boundary violation for a scanner/debugger, especially when used on third-party repositories.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script claims to scan and audit projects, but it also writes AUTO-DEBUG-REPORT.md directly into the target project. Even though this is not code execution, it is an undeclared side effect that modifies user files and can overwrite expected project state or create noisy diffs in repositories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool writes a report file into the target directory without explicit confirmation or a clear safety notice. Silent modification is risky for audit tooling because users may expect read-only behavior, and the write can alter repositories, trigger automation, or overwrite existing artifacts.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/auto-debug.js:216