Back to skill

Security audit

Research Tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed research-agent tracking workflow, with normal but notable risks from installing an unpinned third-party CLI and using broad activation language.

Install only if you trust the 1645labs research-tracker CLI source. Prefer a pinned release or reviewed commit and verify provenance where possible. Use it for deliberate long-running research-agent workflows, not ordinary one-off research tasks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party CLI Installation from Mutable Sources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-17
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

bash
brew tap 1645labs/tap
brew install julians-research-tracker

Or: go install github.com/1645labs/julians-research-tracker/cmd/research@latest

Technical Analysis

The documented installation procedures retrieve and execute third-party software from mutable upstream sources. The Go installation command explicitly uses @latest, so the installed source revision can change after this Skill has been reviewed. The Homebrew procedure similarly adds an external tap and installs its current formula without pinning an immutable revision or requiring artifact signature or checksum verification.

This creates a supply-chain trust gap: the effective code executed by users is not contained in the audited project and is not cryptographically bound to a reviewed version. Although the reviewed file contains no evidence that the current dependency is malicious, a future compromise of the repository, release process, maintainer account, Go module, or Homebrew tap could cause the same documented commands to install attacker-controlled code.

Attack Path

  1. An attacker compromises the upstream repository, maintainer credentials, release pipeline, Go module version, or Homebrew tap.
  2. The attacker publishes a modified release or formula containing malicious installation or runtime behavior.
  3. A user follows the Skill prerequisites and runs either the unpinned Homebrew commands or the go install ...@latest command.
  4. The package manager retrieves the attacker-modified version because no immutable version, checksum, or trusted signature is required.
  5. The resulting binary or installation logic executes with the privileges and environment access of the invoking user.

Impact Assessment

Successful exploitation could provide arbitrary code exe ...[truncated 562 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with a specific, reviewed semantic version or immutable commit:
    bash
    go install github.com/1645labs/julians-research-tracker/cmd/research@vX.Y.Z
    
  2. Pin the Homebrew formula or tap to a reviewed release or commit where operationally feasible.
  3. Publish expected SHA-256 checksums or verifiable release signatures and require users to validate downloaded artifacts before execution.
  4. Use a protected and reproducible release pipeline with signed tags, restricted maintainer access, and provenance attestations.
  5. Document the exact trusted repository, version, artifact digest, and verification procedure in SKILL.md.
  6. Periodically review pinned versions for security updates, and update pins only after reviewing and verifying the new release.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest-style description says the skill 'Triggers on: research projects, sub-agent coordination, autonomous investigation, progress tracking, agent oversight.' These activation terms are high-level and broad, without explicit constraints or negative examples, which could cause the skill to match many ordinary planning or research requests unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.