Back to skill

Security audit

tech-to-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently turns user-selected technical material into generated skill files, with expected source scanning and file creation plus an install command users should treat carefully.

Before installing, prefer a pinned or verified release if available. When using the skill, provide only the files, repos, or URLs you intend the agent to inspect, choose a separate empty output directory, and review the candidate list and generated evidence files before using the resulting skills.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:7
Finding

Unpinned Third-Party Installation Chain

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 7–10
Vulnerability Type: Unpinned npm CLI and mutable repository dependency
Risk Level: Medium

Vulnerable Code

bash
npx skills add LeoGoat2004/tech-to-skill

The same command is also documented in README.zh.md, lines 7–10.

Technical Analysis

The installation command invokes skills through npx without specifying an exact package version. Depending on the local npm configuration and cache state, npx may retrieve and execute the currently published version of that package. The repository argument, LeoGoat2004/tech-to-skill, is also not pinned to an immutable commit SHA or signed release.

Consequently, the effective installation chain can change after this project has been reviewed. A compromise, ownership transfer, or malicious update affecting the npm package or referenced repository could cause users following the documented installation procedure to execute altered installer logic or install modified Skill instructions.

No evidence was found that the current project itself contains a malicious payload. The risk arises from the mutable third-party installation chain documented by the project.

Attack Path

  1. An attacker compromises the npm account or package used by npx, or gains control of the referenced repository.
  2. The attacker publishes malicious installer logic or modifies the repository content.
  3. A user follows the documented installation command.
  4. npx retrieves and executes the current unpinned CLI package.
  5. The CLI retrieves the current mutable repository content.
  6. Malicious code may execute with the invoking user's privileges, or malicious Skill instructions may be installed into the user's Agent environment.

Impact Assessment

Successful exploitation could execute code with the privileges of the user running the installation command. Depending on that user's permissions and the behavior of a compromised installer, the impact cou ...[truncated 378 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the npm CLI to an audited exact version rather than resolving the current release:

    bash
    npx skills@<audited-exact-version> add <immutable-source-reference>
    
  2. Pin the repository content to an immutable commit SHA or a signed release instead of a mutable owner/repository reference.

  3. Publish and document checksums or cryptographic signatures for released Skill artifacts.

  4. Where supported, use a lockfile-backed local installation process and verify package integrity before execution.

  5. Avoid npx auto-install behavior in security-sensitive environments. Install the audited CLI version explicitly, verify it, and then invoke the local binary.

  6. Update both README.md and README.zh.md so all installation examples use the same immutable, verified dependency references.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to run npx skills add LeoGoat2004/tech-to-skill without pinning a specific package or skill version. Unpinned installs can fetch different code over time or resolve to a compromised upstream release, creating a supply-chain risk where users may execute unexpected code during installation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
| Input signal | Sub-skill |
|---|---|
| HTML/PDF long-form with chapters, code blocks, architecture discussion | [`longform-to-skill`](./sub-skills/longform-to-skill/SKILL.md) |
| Paper PDF or blog post with abstract/method/experiment structure | [`paper-to-skill`](./sub-skills/paper-to-skill/SKILL.md) |
| Git repo, ADR directory, retrospective docs, commit history | [`project-docs-to-skill`](./sub-skills/project-docs-to-skill/SKILL.md) |

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
| Input signal | Sub-skill |
|---|---|
| HTML/PDF long-form with chapters, code blocks, architecture discussion | [`longform-to-skill`](./sub-skills/longform-to-skill/SKILL.md) |
| Paper PDF or blog post with abstract/method/experiment structure | [`paper-to-skill`](./sub-skills/paper-to-skill/SKILL.md) |
| Git repo, ADR directory, retrospective docs, commit history | [`project-docs-to-skill`](./sub-skills/project-docs-to-skill/SKILL.md) |

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
| Input signal | Sub-skill |
|---|---|
| HTML/PDF long-form with chapters, code blocks, architecture discussion | [`longform-to-skill`](./sub-skills/longform-to-skill/SKILL.md) |
| Paper PDF or blog post with abstract/method/experiment structure | [`paper-to-skill`](./sub-skills/paper-to-skill/SKILL.md) |
| Git repo, ADR directory, retrospective docs, commit history | [`project-docs-to-skill`](./sub-skills/project-docs-to-skill/SKILL.md) |

The sub-skill files are reference documents for the executing agent, not separately invoked skills. Read the relevant sub-skill before starting Stage 1.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
| Input signal | Sub-skill |
|---|---|
| HTML/PDF long-form with chapters, code blocks, architecture discussion | [`longform-to-skill`](./sub-skills/longform-to-skill/SKILL.md) |
| Paper PDF or blog post with abstract/method/experiment structure | [`paper-to-skill`](./sub-skills/paper-to-skill/SKILL.md) |
| Git repo, ADR directory, retrospective docs, commit history | [`project-docs-to-skill`](./sub-skills/project-docs-to-skill/SKILL.md) |

The sub-skill files are reference documents for the executing agent, not separately invoked skills. Read the relevant sub-skill before starting Stage 1.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
|---|---|
| HTML/PDF long-form with chapters, code blocks, architecture discussion | [`longform-to-skill`](./sub-skills/longform-to-skill/SKILL.md) |
| Paper PDF or blog post with abstract/method/experiment structure | [`paper-to-skill`](./sub-skills/paper-to-skill/SKILL.md) |
| Git repo, ADR directory, retrospective docs, commit history | [`project-docs-to-skill`](./sub-skills/project-docs-to-skill/SKILL.md) |

The sub-skill files are reference documents for the executing agent, not separately invoked skills. Read the relevant sub-skill before starting Stage 1.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
|---|---|
| HTML/PDF long-form with chapters, code blocks, architecture discussion | [`longform-to-skill`](./sub-skills/longform-to-skill/SKILL.md) |
| Paper PDF or blog post with abstract/method/experiment structure | [`paper-to-skill`](./sub-skills/paper-to-skill/SKILL.md) |
| Git repo, ADR directory, retrospective docs, commit history | [`project-docs-to-skill`](./sub-skills/project-docs-to-skill/SKILL.md) |

The sub-skill files are reference documents for the executing agent, not separately invoked skills. Read the relevant sub-skill before starting Stage 1.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to create directories and reference files on disk, but it never explicitly tells the user that filesystem writes will occur before construction begins. Although it asks for an output directory, that is not equivalent to informed consent for file creation and modification, especially when the input may be a repo or docs directory and the agent is instructed to scan broadly. In an agent setting, undisclosed writes can surprise users, overwrite expected workspace contents, or cause unintended persistence of derived artifacts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.