Back to skill

Security audit

AI Demo Recorder

Security checks for vulnerabilities and agentic risk

Overview

This skill is for browser demo recording, but it needs review because it runs mutable npm commands and can upload authenticated recordings while saving reusable login state.

Install only after deciding you are comfortable with screen recordings and metadata leaving your machine by default. Use local-only mode for sensitive or internal apps, avoid production secrets in recordings, treat saved auth files as credentials, and prefer a pinned, reviewed screencli version instead of floating npx commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Third-Party Packages Are Downloaded and Executed Through npx

Content
View full analysis
" [options] ``` ``` ### Technical Analysis The documented commands invoke `screencli` and `skills` through `npx` without specifying exact package versions or integrity hashes. If a package is not already available locally, `npx` may retrieve it from the configured npm registry and immediately execute it. Consequently, the executable code is not fixed to the version reviewed when this Skill was published. A later malicious release, compromised maintainer account, registry compromise, or compromised transitive dependency could change the behavior of these commands without any modification to this repository. This repository contains documentation only and does not contain the implementation of the invoked CLI. The actual package behavior therefore cannot be verified from the audited files. ### Attack Path 1. An attacker compromises the npm package, its maintainer account, its dependency chain, or the registry resolution path. 2. The attacker publishes a malicious version under a package name used by the documented commands. 3. A user or AI Agent follows the Skill and runs an unpinned `npx` command. 4. `npx` resolves and downloads the cu ...[truncated 761 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:55
Finding

Authenticated Recordings Are Uploaded by Default and Browser Session State Is Persisted in Plain JSON

Content
View full analysis
` | — | Save/load auth state by name | | `--local` | off | Skip cloud upload | | `--unlisted` | off | Upload as unlisted (not on public profile) | | `--max-steps ` | `50` | Maximum agent iterations | ``` `SKILL.md:95-119`: ```markdown ## Auth for Private Apps To record behind a login wall, use `--login` and `--auth` together on the first run: ``` npx screencli record https://app.example.com -p "..." --login --auth myapp ``` The browser opens for you to log in manually. Once done, the AI agent takes over and auth state is saved to `~/.screencli/auth/myapp.json`. On subsequent runs, pass just `--auth`: ``` npx screencli record https://app.example.com -p "..." --auth myapp ``` If a session expires, re-run with `--login --auth ` to refresh it. ``` `references/cli-reference.md:143-148`: ```markdown **Location:** `~/.screencli/config.json` Stores authentication token, email, and plan after login. Login is triggered automatically on first `record`, or manually via `npx screencli login`. **Auth state:** `~/.screencli/auth/.json` Stores browser session (cookies, localStorage) for `--auth` reuse. ``` ### Technical Analysis The Skill explicitly supports recording private applications after manual authentication. At the same time, `--local` is off by default, meaning cloud upload is enabled, and `--unlisted` is also off, meaning the documentation does not default uploaded recordings to unlisted visibility. An authenticated recording may display private dashboards, customer records, internal URLs, account details, access tokens s ...[truncated 2430 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (35)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx skills add usefulagents/screencli-skill without pinning a specific package/version, which means the fetched code can change over time and could be replaced by a compromised or malicious release. Because this is installation guidance for an agent skill, users may execute it directly with high trust, increasing supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises automatic screen recording of browser sessions and upload to a shareable link, but does not warn users that recordings may capture secrets, personal data, session tokens, internal URLs, or other sensitive on-screen content. In this skill's context, the risk is elevated because it is specifically designed to automate browser demos and publishing, making accidental data disclosure a realistic outcome.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The command npx screencli record ... invokes an unpinned package/tool version, so behavior and downloaded code may change between runs or if the package registry is compromised. In a tool that automates browser actions and recording/upload, executing an unexpected version could expose sensitive browser content or run unintended code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises automatic upload of polished recordings to screencli.sh, including workflows for private apps, but does not clearly warn that captured browser content, potentially sensitive internal application data, and related metadata may be transmitted to a third-party cloud service. In this context the omission is dangerous because users may assume local processing while actually exporting confidential visuals or business data off-host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill repeatedly instructs users to execute npx screencli ... without pinning an exact package version. Because npx fetches and runs the latest published package by default, a compromised maintainer account, malicious new release, or dependency hijack could result in arbitrary code execution on the user's machine at install/runtime.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This example invokes npx screencli without a pinned version, causing execution of whatever package version npm resolves at that moment. In a security-sensitive workflow that may involve browser automation and stored auth state, that creates a substantial supply-chain and arbitrary code execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx screencli here without version pinning exposes users to package substitution or malicious upstream updates. Since the tool drives a browser and may interact with authenticated sessions, arbitrary code execution could also enable credential theft or exfiltration of captured content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This command again relies on unpinned npx, which downloads and executes code from the npm registry at runtime. If the package or a dependency is compromised, the user's environment, browser session, local files, or authentication artifacts could be exposed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs another unpinned npx screencli execution, which is a classic supply-chain exposure. Because this specific flow uses saved authentication state for private applications, a malicious package version could gain access to privileged sessions and sensitive internal data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The export command uses unpinned npx screencli, so users may execute an unreviewed package version when processing local recording assets. A malicious update could tamper with files, exfiltrate recordings, or run arbitrary code under the user's account.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This login/auth workflow is documented with unpinned npx, compounding supply-chain risk with authenticated browser access. A malicious or compromised package version could capture credentials, cookies, or session tokens during the manual login flow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The subsequent-run command still uses floating npx, allowing a later malicious release to exploit previously saved auth state. This increases risk because a user may trust the tool after initial setup while later executions silently pull changed code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that reusable auth state is saved to ~/.screencli/auth/myapp.json but does not warn users that this file may contain session material that grants access to private applications. If mishandled, copied, or read by malware or other local users, the stored state could enable account takeover or unauthorized access to internal systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Refreshing an expired session via unpinned npx again executes mutable registry code during an authentication-related operation. That combination materially raises the chance of credential or token theft if the package supply chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The cloud login command uses unpinned npx, so users may authenticate against the service while running an unverified package build. This could permit token theft or arbitrary code execution, though the direct impact is somewhat narrower than full browser automation with saved app auth.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Even the logout command normalizes use of floating npx packages. While less sensitive than login, it still conditions users to execute mutable remote code directly from npm, preserving the same arbitrary code execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The whoami command is also unpinned and would execute whatever current package version resolves from the registry. An attacker controlling a malicious release could harvest account information or run code locally even through a seemingly harmless status command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Listing recordings via unpinned npx still executes untrusted mutable code from npm. If compromised, it could enumerate cloud assets and exfiltrate links or local credentials while appearing to perform a benign query.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The upload command combines unpinned package execution with transmission of local recording artifacts. A malicious package version could exfiltrate additional files or modify upload contents beyond the user's intent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Deleting cloud recordings through unpinned npx continues the same supply-chain problem. Although the command's stated function is limited, malicious code could still execute locally or abuse authenticated cloud access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Re-rendering in the cloud via unpinned npx executes mutable code while handling authenticated account actions and potentially sensitive recording metadata. A compromised release could abuse cloud permissions or steal tokens and local data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The troubleshooting step tells users to run npx screencli record without version pinning, reinforcing insecure operational habits. Troubleshooting commands are often copied verbatim, so this still exposes users to arbitrary code execution from a mutable registry package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This second unpinned npx screencli occurrence on the same line is also a true supply-chain vulnerability because it executes mutable registry content. The fact that it appears in troubleshooting guidance does not reduce the underlying arbitrary code execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documentation repeatedly instructs users to run npx screencli without a pinned package version. npx may fetch the latest published package at execution time, so a compromised upstream release, dependency hijack, or malicious republish could execute arbitrary code on the user's machine. In this skill, the risk is elevated because the tool handles browser automation, local files, auth tokens, and session state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx screencli without version pinning causes execution to depend on whatever version is current in the registry at runtime. If the package or one of its transitive dependencies is compromised, users may unknowingly run attacker-controlled code. Because this CLI can record browser sessions and interact with cloud services, compromise could expose sensitive local and browser data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.