Back to skill

Security audit

Find Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a skill-discovery helper, but it encourages broad triggering and global third-party skill installation through an unpinned command-line tool with limited user safety checks.

Review this skill before installing. It is not malicious on its face, but it can lead an agent to run unpinned package-manager commands and globally install third-party skills. Prefer using a pinned, trusted Skills CLI version, review the exact skill source before installation, avoid `-g -y` unless you intentionally want global persistence and skipped prompts, and use explicit confirmation for each install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Third-Party CLI Execution and Unverified Global Skill Installation

Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` From `SKILL.md`, lines 87–93: ```markdown ### Step 4: Offer to Install If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` ``` ### Technical Analysis The skill instructs the agent to invoke `npx skills` without specifying an exact package version or verifying package integrity. When the package is unavailable locally, `npx` may retrieve and execute the package resolved by the configured npm registry. Consequently, the code executed at audit time may differ from the code executed later. The instructions also permit skills to be installed from GitHub or unspecified “other sources.” They do not require verification of the repository owner, immutable commit, release signature, checksum, package contents, or install scripts. The recommended `-g -y` options increase risk by installing at user-global scope and suppressing interactive confirmation. This creates a supply-chain trust boundary in which a compromised package, malicious source repository, dependency-confusion package, or typo-squatted package could cause attacker-controlled code to execute under the account running the agent. ### Attack Path 1. An attacker publishes, replaces, or compromises the package resolved as `skills`, one of its transitive dependencies, or a skill repository returned by the external discovery service. 2. A user asks the agent to find or install a relevant skill. 3. Following `SKILL.md`, the agent executes an unpinne ...[truncated 1390 chars]
Remediation
View remediation
`, and update the version only through a controlled review process. 2. Verify registry provenance, release signatures where available, and package integrity hashes before execution. 3. Use an organizational allowlist of approved package owners, repositories, and skill identifiers. 4. Resolve GitHub installations to reviewed immutable commit hashes rather than mutable branches or tags. 5. Inspect package contents, manifests, lifecycle scripts, and transitive dependencies before installation. 6. Remove `-g -y` from the default workflow. Prefer local, isolated installation with explicit user confirmation. 7. Run discovery and installation in a sandbox with minimal filesystem, credential, environment-variable, and network access. 8. Present the resolved source, exact version or commit, requested scope, and security implications to the user before installation. 9. Disable or tightly control package lifecycle scripts where supported. 10. Document a rollback procedure for removing installed skills and restoring affected user-level configuration. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level description activates on very broad phrases like 'how do I do X' and general interest in extending capabilities. That can cause the skill to trigger in many unrelated conversations and steer the agent toward discovering/installing third-party skills when direct assistance would be safer, creating unnecessary exposure to external package sources.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'when to use' section is ambiguous and lacks scope boundaries, so the skill may activate for ordinary capability questions rather than only explicit marketplace/package-management requests. In this context that matters because activation funnels users toward external discovery and installation workflows, increasing the chance of unnecessary supply-chain interactions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning an exact package version, which causes code to be fetched and executed from the registry at runtime. That creates a supply-chain risk: a compromised package, dependency, or newly published breaking/malicious version could be executed in the user's environment simply by following the skill guidance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using unpinned npx skills for package-management actions means the command resolves whatever version is current at execution time. In a skill whose purpose is discovering and installing more code, this increases the attack surface because the bootstrap tool itself is not fixed to a reviewed version.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command example invokes an unversioned remote CLI, allowing silent drift to future versions or maliciously altered releases. Because users are encouraged to use it as the package manager for skills, compromise of this entrypoint could directly lead to arbitrary code execution or malicious skill installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The update/check workflow still relies on an unpinned npx invocation, so even benign maintenance actions may execute unreviewed code from the package registry. This is a classic supply-chain exposure rather than a direct exploit in the markdown itself, but it is a real security issue in operational guidance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

An unpinned npx skills update example compounds risk because it both runs an unpinned bootstrap tool and performs broad updates. If the CLI or update logic is compromised, users could fetch and install multiple malicious components in one step.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The search instruction uses npx skills find [query] without pinning the package version, so even a read-only discovery action requires execution of remote code that may change over time. In this context, discovery is the gateway to later installations, so trust in the bootstrap command is especially important.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This concrete example normalizes running an unpinned remote CLI for common user tasks. Repetition increases the chance that users copy-paste the insecure pattern, making supply-chain compromise more likely to propagate at scale.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill presents another unpinned npx skills find example, again allowing arbitrary future package versions to run. While the command looks low risk, the underlying execution model is not, because npx installs and runs code before the user can meaningfully assess it.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Even a simple search example like this still relies on unreviewed runtime package resolution. Given that the skill is explicitly about extending capabilities by installing third-party packages, insecure bootstrap guidance materially raises the danger of downstream compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The generated install instruction recommends npx skills add <owner/repo@skill> without pinning the CLI version or constraining the skill source beyond owner/repo text. This encourages direct installation of third-party code through a mutable toolchain, increasing supply-chain and typo/repo-confusion risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This is the highest-risk instance because it actively instructs installation of a skill via an unpinned remote CLI. Following it could execute an unreviewed CLI version and then install additional third-party code, creating a clear path to arbitrary code execution or persistence in the user's environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installation section tells the agent it 'can install the skill for them' using global install and skipped confirmations, but it does not warn the user about the trust, persistence, and scope implications. This creates a high-risk pattern of silently installing third-party code system-wide with reduced user awareness and consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

npx skills add <owner/repo@skill> -g -y is especially dangerous because it combines an unpinned bootstrap tool with global installation and suppressed prompts. This reduces user visibility and friction around installing executable content system-wide, magnifying the impact of any compromised CLI or malicious skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The guidance to initialize a new skill via unpinned npx skills init still executes mutable remote code. Although initialization is less dangerous than installation, it remains a supply-chain entrypoint and should not rely on an unversioned runtime fetch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This repeated npx skills reference reinforces the insecure pattern of executing an unpinned remote package. The issue is contextual: because the entire skill centers on acquiring more code, weak trust controls at the first step are meaningfully dangerous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.