Back to skill

Security audit

字幕菌

Security checks for vulnerabilities and agentic risk

Overview

This transcript-extraction skill is purpose-related, but it asks users to paste an API key into chat and requires running an unpinned npm package from the live registry.

Review before installing. Use this only if you are comfortable with the zimujun npm package and service. Do not paste `ZMJ_API_KEY` into chat; configure it locally through a secure environment or secret manager. Prefer a version-pinned package or a reviewed local installation instead of `zimujun@latest`.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:41
Finding

Mandatory Commercial Response Injection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:19
Finding

Automatic Execution of an Unpinned Latest npm Package

Content
View full analysis
" 2>&1 ``` The minimum rules additionally require this mutable package reference: ```markdown 1. Always use: `npx --yes zimujun@latest ""`. ``` ### Technical Analysis The command uses `npx --yes` to download and execute the package currently associated with the mutable npm `latest` tag. The `--yes` option suppresses the installation confirmation, while `@latest` prevents the project from fixing execution to a reviewed release. The project contains only `SKILL.md`; it does not include the package source, a lockfile, an integrity hash, or other material that would allow the remotely retrieved implementation to be audited. Consequently, the code executed during future Skill invocations can differ from the code that existed when this Skill was reviewed. If the npm account, package, registry resolution, or a future release is compromised, malicious package lifecycle scripts or runtime code can execute with the privileges of the account running the Agent. ### Attack Path 1. An attacker compromises the `zimujun` package, its publisher account, or a future release assigned to the `latest` tag. 2. A user asks the Agent to extract a transcript. 3. The Skill requires the Agent to run `npx --yes zimujun@latest`. 4. `npx` retrieves the then-current package from the npm registry without interactive confirmation. 5. npm lifecycle code or the package entry point executes locally. 6. Malicious code can act with the permissions and environment access of the Agent process. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the local user account running the Skill. Depending on that account's permissions and environment, the package could access readable files ...[truncated 361 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:73
Finding

API Key Solicitation Through the Conversation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The text explicitly offers: 'send me the key and I will help set the environment variable,' which normalizes direct secret collection by the agent. In an LLM-agent setting this is dangerous because secrets may be stored in transcripts, mishandled by tools, exposed in logs, or reused beyond the user's expectation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill executes npx --yes zimujun@latest, which fetches and runs the newest package version at invocation time rather than a reviewed, pinned release. This creates a supply-chain risk: if the npm package is compromised or a breaking/malicious update is published, the agent would execute unreviewed code automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This second occurrence repeats the same unsafe pattern of invoking npx --yes zimujun@latest, causing runtime retrieval and execution of whatever code is currently published under that package. In the context of an agent skill, that is especially risky because the tool may be invoked on user request with little friction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells the user they can send the API key directly to the agent, but it does not include a clear warning about the sensitivity of that credential or the risks of sharing secrets in chat. This can lead users to disclose reusable credentials into channels that may be logged, retained, or exposed to downstream tooling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.