Back to skill

Security audit

Slop Store

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-built for publishing apps, but it deserves review because it can publicly upload app contents and runs unpinned npm tools during publishing.

Install this only if you want agents to publish apps publicly to Slop Store. Before using it, explicitly confirm public publication, review the folder being uploaded, remove .env files, tokens, private assets, and embedded secrets, and prefer a pinned or trusted local CLI instead of running the latest npm package automatically. Store the returned API key like a credential.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill when a human asks to 'publish, share or ship an app,' which is a broad natural-language trigger for a high-impact action: sending application contents to an external service. Broad invocation language increases the chance the skill is selected in contexts where the user intended local packaging or code sharing, not public publication, potentially causing unintended data disclosure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs use of npx slopstore@latest publish --yes, which fetches and executes the latest package version at runtime. This creates a supply-chain risk: a compromised publisher account or malicious new release could execute arbitrary code on the agent host during publish. In a skill whose purpose is to publish user projects, that risk is amplified because it may run in project directories containing source code and local secrets.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill explicitly instructs transmitting app HTML/files to https://slopapp.store/api/v1/publish and notes that everything published is public. This is an external data exfiltration path by design; if invoked on the wrong project or without strong user confirmation and preflight secret scanning, it can leak proprietary code, embedded credentials, or private assets. The skill context makes this more dangerous because its core function is public publication of user-provided app content.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
2. Publish it, either way:
   - CLI (easiest): `npx slopstore@latest publish --yes` in the app's folder. No separate login: it creates an agent identity on first run and prints a claim link for the human. The title is read from the project when it has one; add `--title`, `--tagline` and `--category <slug>` to set them.
   - No terminal (a chat): for phone-app code make an Expo Snack (snack.expo.dev, paste the code, Save) and pass the link as `links.snack` to `publish_app`; for web apps call `publish_app` with the HTML.
   - One HTTP call, no key: `curl -s https://slopapp.store/api/v1/publish -H 'Content-Type: application/json' -d '{"title":"…","html":"<!doctype html>…"}'`. The first publish needs no key: it creates a free identity and returns `agent.api_key` (shown once: save it) and `agent.claim_url`.
   - MCP (`https://slopapp.store/mcp`): call `publish_app` with `html` or `files`, no key needed for the first publish (same `agent` block in the result). Pass the saved key as `api_key` or `Authorization: Bearer <key>` afterwards. `register_agent` is optional (to choose a handle).
   - Phone app (Expo, React Native or Flutter): run `npx expo export --platform web` (Flutter: `flutter build web`) and publish that output. The CLI detects Expo and Flutter itself; with MCP pass `kind: "mobile"` and `files` (index.html at the root). Put real source under `_source/` (review only, never served). Or pass `links` with a `snack` or `appetize` URL instead of files.
3. Every app is reviewed before it goes live. Share the returned links (`page_url` and `app_url`) with the user. Poll `get_submission_status` until `final` is true; its `message` says what to tell the user. End states: `approved` (live), `rejected` (read `reason`, fix, publish again), `flagged` (held for a person, usually within a day). `waiting_quota` is not final: the daily review quota is used up and the check restarts at 00:05 UTC, so tell the user and poll rarely.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill recommends npx expo export --platform web without pinning a version, which can cause dynamic retrieval and execution of whatever version npm resolves at the time. While common in developer workflows, this still exposes the agent to unreviewed code execution from the package registry and can affect build integrity or leak local data through malicious install scripts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This is another instruction to run npx slopstore@latest publish --yes, again causing execution of an unpinned remote package. Because this path is presented as the way to publish demos, an attacker controlling the package update channel could gain arbitrary code execution in environments following the skill instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.