Back to skill

Security audit

Find Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it encourages broad, global installation of third-party skills through unpinned commands that can change over time.

Review carefully before installing. This skill is not malicious in the inspected artifact, but it can lead an agent to run mutable `npx` commands and globally install third-party skills. Prefer pinned CLI versions, inspect any skill source before installation, avoid `-g -y` by default, and only install from maintainers you trust.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Third-Party CLI and Unverified Global Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24-33 and 78-83
Vulnerability Type: Supply-chain exposure through unpinned executable dependencies and unverified external packages
Risk Level: Medium

Vulnerable Code

markdown
**Key commands:**

- `npx skills find [query]` - Search for skills interactively or by keyword
- `npx skills add <package>` - Install a skill from GitHub or other sources
- `npx skills check` - Check for skill updates
- `npx skills update` - Update all installed skills
markdown
If the user wants to proceed, you can install the skill for them:

```bash
npx skills add <owner/repo@skill> -g -y

The -g flag installs globally (user-level) and -y skips confirmation prompts.

text

### Technical Analysis

The Skill directs the agent to execute `npx skills` without pinning the CLI package to a reviewed version or integrity digest. When the package is not already available locally, `npx` can retrieve and execute the currently published npm package, including package lifecycle behavior. The effective executable can therefore change after this Skill has been audited.

The installation workflow accepts packages from GitHub or unspecified other sources without requiring repository allowlisting, immutable commit references, integrity verification, or a security review of the downloaded contents. It also recommends `-g`, which creates persistent user-level installation state, and `-y`, which suppresses the CLI confirmation prompt.

This is a supply-chain weakness rather than evidence that the currently documented package is malicious. Exploitation depends on compromise or malicious control of the CLI package, a discovered Skill package, its repository, or another accepted distribution source.

### Attack Path

1. An attacker publishes or compromises a release of the package resolved by `npx skills`, or causes a malicious Skill package or repository to ap
...[truncated 1189 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specifically reviewed version, for example npx skills@<approved-version>, and verify the package with a lockfile and trusted integrity digest where supported.
  2. Maintain an allowlist of approved package owners, repositories, and registries. Do not permit installation from unspecified sources by default.
  3. Resolve GitHub-hosted Skills to reviewed immutable commit hashes rather than mutable branches, tags, or search-result identifiers.
  4. Download and inspect each Skill before installation, including its instructions, scripts, lifecycle hooks, dependencies, external URLs, and requested permissions.
  5. Require explicit, informed user approval after displaying the exact source, resolved version or commit, installation scope, and security implications.
  6. Remove -y from the default workflow so confirmation is not automatically bypassed.
  7. Avoid -g by default. Install into an isolated project directory, sandbox, container, or other least-privilege environment.
  8. Disable or restrict package lifecycle scripts where practical and run third-party tooling with limited filesystem, credential, and network access.
  9. Record and verify hashes of approved artifacts so unexpected upstream changes block installation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are overly broad, including ordinary requests like 'how do I do X' and 'can you do X', which can cause this skill to activate when the user is simply asking for direct help. Unintended invocation is risky here because the skill steers toward searching for and installing external tooling, potentially escalating from a benign question into unnecessary package execution or installation suggestions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to Use This Skill' section uses ambiguous conditions like wanting help with a domain or asking whether the agent can do something, without clear boundaries. In this context, ambiguity increases the likelihood that users are funneled into external skill discovery and installation workflows when no such escalation was requested.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a specific package version, which means execution depends on whatever version is current in the registry at runtime. In a package-manager context, this creates a supply-chain risk: a compromised or maliciously updated package could be fetched and executed when the skill is followed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command reference uses npx skills without a pinned version, allowing whatever latest package version resolves at execution time. Because npx may download and run code immediately, this exposes users to upstream compromise or unexpected behavior changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill advertises npx skills add <package> without pinning the CLI version, so users may run a different binary over time. In a workflow that installs additional packages from external sources, an unpinned package manager compounds supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx skills check without a pinned version can execute newly published code from the registry rather than a reviewed version. Even read-oriented operations still require trusting downloaded code, so the absence of pinning is a genuine security weakness.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The npx skills update example executes an unpinned package manager command that can change both the tool and installed skills over time. This creates a broad supply-chain and change-control risk, especially because update paths are attractive targets for malicious package publication.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This search instruction tells the agent/user to run npx skills find [query] without locking the version of the executed package. Because the skill's core behavior depends on this command, the context makes the unpinned execution path especially central and therefore more dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The example command for React performance discovery uses unpinned npx skills, which leaves command behavior and executed code subject to registry changes. While this line is an example, users often copy-paste such examples directly, so the risk is practical rather than theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This PR review example again relies on npx skills without version pinning, enabling unreviewed remote code execution through package resolution. Repetition across multiple examples increases the likelihood users will adopt the unsafe pattern broadly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The changelog example uses the same unpinned execution pattern, exposing users to supply-chain compromise via the registry. Since the skill is designed to encourage discovery and installation of third-party extensions, even seemingly harmless example commands contribute to a risky trust model.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command shown to users invokes npx skills add without pinning the package manager version, increasing the chance that an attacker controlling or compromising the package can influence installation behavior. Because this command directly installs additional code, the impact is higher than a passive documentation issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The instruction npx skills add <owner/repo@skill> -g -y combines unpinned remote code execution with global installation and prompt suppression. This is especially dangerous because it reduces friction for system-wide changes while preventing an interactive review step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs a global, non-interactive install command using -g -y without a clear warning about system-wide impact, trust implications, or confirmation from the user. This is dangerous because it enables silent installation of third-party code at user scope, reduces friction for unsafe changes, and pairs with unpinned npx execution to amplify supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Even in advisory text, npx skills init is presented without version pinning, perpetuating the pattern of executing registry-fetched code opportunistically. Although initialization is less dangerous than installation, it still trusts transient remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This later reference continues to normalize unpinned npx skills usage, reinforcing an unsafe operational pattern throughout the skill. In aggregate, repeated unpinned examples materially increase the chance of insecure user behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The final reference still instructs execution of npx skills without constraining version or source integrity. Because the skill's purpose is to direct users toward installing tooling, the lack of pinning remains a real supply-chain concern in context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.