Back to skill

Security audit

Security Auditor

Security checks for vulnerabilities and agentic risk

Overview

This security-auditing skill is mostly purpose-aligned, but it mixes review-only metadata with instructions to make sensitive security and dependency changes, including unpinned npm tool execution.

Install only if you want a security-review assistant that may advise changes in sensitive parts of a project. Treat its dependency commands as suggestions, not automatic steps: pin or use locally locked tools, review any package changes, and require explicit approval before modifying auth, secrets, middleware, database schema, or package files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:347
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:347-355
Vulnerability Type: Supply-chain exposure through unpinned executable dependencies
Risk Level: Medium

Vulnerable Code

bash
# Regular audit
npm audit
npm audit fix

# Check for known vulnerabilities
npx better-npm-audit audit

# Keep dependencies updated
npx npm-check-updates -u

Technical Analysis

The Skill recommends executing third-party packages through npx without specifying reviewed versions or requiring installation from a locked dependency manifest. If these packages are not already installed locally, npx can retrieve and execute package code from the configured npm registry.

This makes the effective executable payload dependent on the package version and registry state at invocation time rather than on content included in the audited Skill. A compromised maintainer account, malicious package release, registry compromise, or unsafe registry configuration could therefore result in execution of unreviewed code.

The npm-check-updates -u command also modifies dependency declarations. Such modification exceeds the permissions required for a read-only security audit unless the user explicitly authorizes project changes.

Attack Path

  1. An attacker compromises a referenced package, its publisher account, or the package registry used by the environment.
  2. The attacker publishes a malicious version or causes package resolution to return attacker-controlled content.
  3. A user follows the Skill instructions and runs the unpinned npx command.
  4. npx downloads the currently resolved package because no trusted local version is available.
  5. The package's executable code runs with the privileges of the invoking user.
  6. The malicious code can access files, environment variables, credentials, and network resources available to that user.
  7. In the update command's case, dependency declarations may also be changed wit ...[truncated 554 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin every recommended executable package to a specifically reviewed version.
  • Declare tools in a dependency manifest and commit the corresponding lockfile.
  • Use npx --no-install or an equivalent mechanism to prohibit implicit network installation.
  • Verify package integrity and provenance before adding or upgrading audit tools.
  • Run dependency-analysis tools in a sandbox with minimal filesystem, credential, and network access.
  • Separate read-only auditing from dependency modification.
  • Require explicit user approval before running npm audit fix or npm-check-updates -u.
  • Review generated manifest and lockfile changes before installation or execution.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:306
Finding

Spoofable Forwarded IP Address Used as a Remote Rate-Limit Identifier

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:306-316
Vulnerability Type: Untrusted proxy-header usage and external processing of client identifiers
Risk Level: Medium

Vulnerable Code

typescript
import { Ratelimit } from '@upstash/ratelimit'
import { Redis } from '@upstash/redis'

const ratelimit = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.slidingWindow(10, '10 s'),
})

// In middleware or route handler
const ip = request.headers.get('x-forwarded-for') ?? '127.0.0.1'
const { success, remaining } = await ratelimit.limit(ip)
if (!success) {
  return NextResponse.json({ error: 'Too many requests' }, { status: 429 })
}

Technical Analysis

The example uses the raw x-forwarded-for request header as the rate-limit key. This header is attacker-controlled unless the application is deployed behind a trusted reverse proxy that removes client-supplied forwarding headers and reconstructs them from the actual connection address.

An attacker can submit a different header value for each request, causing the rate limiter to treat requests from one client as requests from many clients. The example also does not parse a trusted position in a proxy chain or validate that the supplied value is an IP address.

Redis.fromEnv() configures an external Redis client using environment-provided endpoint and authentication data. Calling ratelimit.limit(ip) can transmit the selected identifier to that configured service. This network communication is relevant to distributed rate limiting, but the example omits privacy, data-minimization, retention, and deployment-trust requirements. Misconfiguration could therefore disclose client identifiers to an unintended Redis endpoint.

Attack Path

  1. An application adopts the example without deploying a trusted proxy that sanitizes forwarding headers.
  2. An attacker sends requests with a chosen X-Forwarded-For value.
  3. For each req ...[truncated 1107 chars]
Remediation
View remediation

Remediation Suggestions

  • Obtain the client address from a trusted framework or hosting-platform API rather than directly trusting a request header.
  • Configure the edge proxy to remove incoming forwarding headers and create canonical forwarding metadata.
  • Define the exact number and identity of trusted proxies before selecting an address from a forwarding chain.
  • Parse and validate the resulting address as IPv4 or IPv6 data.
  • Do not use the loopback address as a shared fallback key; reject unavailable identity data or apply a separate conservative limit.
  • Combine IP-based controls with account, session, device, or endpoint-level limits where appropriate.
  • Restrict Redis configuration to an allowlisted TLS endpoint and use credentials scoped only to rate-limiting data.
  • Minimize or pseudonymize identifiers before remote storage when operationally feasible.
  • Establish expiration, retention, access-control, and privacy requirements for remotely stored rate-limit keys.
  • Document that external Redis communication is required for distributed rate limiting and obtain explicit deployment approval.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

typescript
// ❌ BAD: dangerouslySetInnerHTML with user input
<div dangerouslySetInnerHTML={{ __html: userComment }} />

// ✅ GOOD: Sanitize HTML
import DOMPurify from 'isomorphic-dompurify'

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

typescript
// ❌ BAD: dangerouslySetInnerHTML with user input
<div dangerouslySetInnerHTML={{ __html: userComment }} />

// ✅ GOOD: Sanitize HTML
import DOMPurify from 'isomorphic-dompurify'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

md
return new SignJWT(payload)
    .setProtectedHeader({ alg: 'HS256' })
    .setIssuedAt()
    .setExpirationTime('15m')  // Short-lived access tokens
    .setAudience('your-app')
    .setIssuer('your-app')
    .sign(secret)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list contains broad terms like security, audit, secrets, and validate input, which may match many normal conversations and cause unintended activation. For a high-trust security skill, accidental invocation can expose sensitive code paths, override more appropriate specialist routing, or encourage overbroad handling of unrelated requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest declares scope: review, but the skill instructions explicitly direct the agent to design and implement authentication, input validation, encryption, tests, and monitoring. This scope mismatch can cause an ostensibly review-only skill to make code changes or provide modification-oriented guidance beyond its declared trust boundary, increasing the risk of unsafe autonomous actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill recommends executing npx better-npm-audit without pinning a specific package version. Because npx fetches and runs the latest package by name, a future malicious package update, dependency compromise, or typo-squat scenario could result in arbitrary code execution on the reviewer’s machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation suggests npx npm-check-updates -u without a pinned version. This causes remote package resolution at execution time and may expose users to arbitrary code execution if the upstream package or its dependency chain is compromised.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:91