Back to skill

Security audit

find-skills-gitcode

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent skill-discovery helper, but it needs review because it encourages broad activation, unpinned remote CLI execution, and non-interactive global installs.

Install only after confirming you want this skill to help discover and install other skills. Treat its commands as software-installation actions: pin or verify the CLI version, inspect target skills before adding them, avoid `-g -y` unless you explicitly want a persistent global install, and prefer an isolated environment for testing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Third-Party CLI Execution and Unattended Global Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23–30, 57, 91, and 101
Vulnerability Type: Supply-chain exposure through unpinned runtime dependencies and unsafe third-party installation
Risk Level: Medium

Vulnerable Code Snippets

markdown
The Skills CLI (`npx skills-gitcode`) is the package manager for the open agent skills ecosystem.

**Key commands:**

- `npx skills-gitcode find [query]` - Search for skills interactively or by keyword
- `npx skills-gitcode add <package>` - Install a skill from GitHub or other sources
- `npx skills-gitcode check` - Check for skill updates
- `npx skills-gitcode update` - Update all installed skills
bash
npx skills-gitcode find [query]
bash
npx skills-gitcode add vercel-labs/agent-skills@react-best-practices
bash
npx skills-gitcode add <owner/repo@skill> -g -y

Technical Analysis

The Skill instructs the agent to execute skills-gitcode through npx without pinning an exact reviewed package version or validating package integrity. Depending on local npm behavior and cache state, npx may retrieve and execute package content from the configured registry at runtime. Consequently, the code executed can differ from the code that existed when this Skill was reviewed.

The installation workflow also permits packages from “GitHub or other sources” and recommends -g -y. The -g option broadens the installation scope to the user-level global environment, while -y suppresses the confirmation prompt that would otherwise provide a final review point.

The document recommends checking installation counts, repository stars, and source reputation. Those signals can assist selection, but they do not provide cryptographic integrity, immutable versioning, provenance verification, or a security review of the installed content. A popular or reputable dependency can still be compromised.

Attack Path

  1. A user asks the agent to discover or install functionality provided by ...[truncated 1528 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an exact, independently reviewed version, for example npx skills-gitcode@X.Y.Z, rather than resolving the latest available release.
  2. Use a lockfile or equivalent integrity mechanism and verify package checksums, signatures, provenance attestations, publisher identity, and the canonical source repository.
  3. Maintain an explicit allowlist of approved Skill repositories, versions, and commit hashes. Do not permit arbitrary “other sources” by default.
  4. Download and statically inspect each Skill’s instructions, scripts, dependencies, hooks, and installation behavior before enabling or executing it.
  5. Remove -y from the default workflow and require explicit, informed user approval immediately before installation.
  6. Avoid -g by default. Install into an isolated, task-specific environment with minimum filesystem, credential, process, and network permissions.
  7. Resolve GitHub-based installations to immutable reviewed commit hashes rather than mutable branches or tags.
  8. Treat installation counts, stars, and author reputation only as supplementary indicators, not as security controls.
  9. Add rollback and removal procedures for installed Skills and record the exact source, version, hash, and approval associated with every installation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level description says the skill should be used whenever users ask broad questions like 'how do I do X' or express interest in extending capabilities. Those triggers overlap heavily with ordinary assistance requests, so the skill may activate in many unrelated contexts and steer the agent toward package discovery or installation unnecessarily.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 'When to Use This Skill' section uses expansive cues like 'can you do X' and 'mentions they wish they had help,' which are ambiguous and likely to over-trigger. In context, over-activation is risky because the skill's next steps involve external search and optional software installation, increasing exposure from otherwise harmless conversations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill repeatedly instructs use of npx skills-gitcode without pinning an exact version, which causes code to be fetched and executed at runtime from the registry. If the package is compromised, typosquatted, or updated maliciously, users or agents could execute attacker-controlled code during search, install, update, or initialization flows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This command references npx skills-gitcode without a pinned version, so execution depends on whatever package version is current at invocation time. That creates a supply-chain execution risk because the package manager may download and run unreviewed code from an external source.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using an unpinned npx package for installation commands is risky because it executes package code before the user can assess the fetched version. In a discovery-and-install skill, this is especially sensitive because it normalizes remote package execution as part of routine use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

An unpinned npx skills-gitcode check command allows arbitrary newer package versions to run during update checks. Even seemingly read-only operations still execute the package's code and can therefore expose the host to supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The update command uses npx skills-gitcode without version pinning, combining remote code execution with a workflow that changes installed software. This increases the blast radius because a compromised CLI could both execute and alter local agent behavior or installed skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The example search command again uses an unpinned npx package, which exposes the environment to execution of whatever version is currently published. In this skill, repeated examples reinforce insecure operational habits and make accidental unsafe execution more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This example encourages users to run an unpinned remote package for React-related search. The danger is not in the query but in the package execution model: npx may fetch and run attacker-controlled code if the dependency is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill presents another unpinned npx skills-gitcode example, perpetuating runtime dependency ambiguity. Because this skill is designed to be copied verbatim into user workflows, these examples materially increase supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This unpinned search example remains a true supply-chain risk because npx executes the CLI package itself. Repetition throughout the file makes the unsafe pattern systematic rather than incidental.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command shown to users uses npx skills-gitcode add ... without pinning the CLI version, which is especially dangerous because it both executes remote code and installs additional content. An attacker controlling the CLI package or its resolution path could gain code execution and influence subsequent installed skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the agent to offer installation using npx skills-gitcode add <owner/repo@skill> -g -y but does not clearly require a warning that this performs a global, non-interactive system modification. In an agent environment, that can lead to software being installed persistently with reduced user awareness or consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This command combines an unpinned npx package with -g -y, enabling non-interactive global installation after fetching executable code from the network. In an agent context, that substantially raises risk because compromise can become persistent and occur without an adequate confirmation barrier.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Even the suggestion to create a new skill via unpinned npx skills-gitcode init executes the remote CLI package. Although initialization may seem lower risk than install/update, it still grants code execution to an unreviewed latest package version.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The tips section again normalizes a floating npx invocation model for the CLI. Because users often copy examples directly, this broadens exposure to registry compromise or malicious package updates over time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.