Back to skill

Security audit

SkillGuard Security Scanner

Security checks for vulnerabilities and agentic risk

Overview

The skill is a small security-scanner wrapper, but it tells users to run an unpinned external npm CLI as the core behavior, so the reviewed artifact does not fully define the code that will execute.

Install only if you are comfortable with the npm package `skillguard-audit` executing with your user permissions. Prefer a pinned reviewed version, a lockfile-backed install, and an isolated environment without unnecessary credentials when auditing local skill folders.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:33
Finding

Unpinned npm Package Is Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 33–43
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
# Audit by skill name
npx skillguard-audit --name <skill-slug>

# Audit local skill folder
npx skillguard-audit --path ./my-skill
bash
# Start the API server
npx skillguard-audit serve --port 3402

Technical Analysis

The documented commands delegate all security-scanning and API-server functionality to the external skillguard-audit npm package without specifying an exact package version. When the package is unavailable locally, npx may offer to download it from the configured npm registry and then execute its package lifecycle or CLI code.

Consequently, the code executed by users is not immutable and may differ from the version that existed when this skill was audited. A compromised package release, package ownership transfer, registry compromise, or unsafe registry configuration could replace the expected scanner with attacker-controlled code.

The project contains only SKILL.md and does not include a local implementation against which the advertised scanning behavior can be verified.

Attack Path

  1. An attacker compromises the skillguard-audit package, its publisher account, or the package source selected by the user's npm configuration.
  2. The attacker publishes a malicious version under the same package name.
  3. A user follows one of the documented unversioned npx skillguard-audit commands.
  4. npx resolves the current package version and, if it is not already available locally, downloads it from the configured registry.
  5. The downloaded package executes with the permissions of the user running the command.
  6. Malicious package code can inspect supplied skill directories, read other files accessible to that user, initiate network connections, alter user-owned files, or execute addition ...[truncated 671 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to an exact, reviewed version rather than invoking an unconstrained package name.
  • Prefer declaring the package in a local package.json, committing a lockfile with integrity metadata, installing with npm ci, and invoking the lockfile-resolved local binary.
  • Disable or avoid implicit package installation during execution. Ensure the command fails if the reviewed dependency is not already installed.
  • Verify the package publisher, official repository, provenance attestations, and registry source before installation.
  • Use npm integrity checks and a trusted registry configuration; review dependency and transitive-dependency changes before updating the lockfile.
  • Execute the scanner with least privilege in an isolated environment with restricted filesystem access, limited environment variables, no unnecessary credentials, and controlled network access.
  • Document the exact package version and source that correspond to the skill's reviewed release.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill documentation instructs users to execute npx skillguard-audit without pinning an exact package version. Because npx will fetch the latest published package if it is not already installed, a compromised upstream release or typo-squatted package could result in unreviewed code execution on the user's system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

This command again relies on unpinned npx execution for a local audit workflow. Unpinned transient package execution creates supply-chain risk because the command may download and run whatever version is current at execution time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Starting the API server via npx skillguard-audit serve --port 3402 also executes an unpinned package from the registry. If the package is replaced, hijacked, or a malicious similarly named package is resolved, this could lead to arbitrary code execution in the environment running the command.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

npx skillguard-audit serve --port 3402

Audit via API

curl -X POST http://localhost:3402/api/audit -d '{"name": "some-skill"}'

text

## Verdict

Static analysis

No suspicious patterns detected.