Back to skill

Security audit

AnyGen Suite

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real AnyGen content-generation skill, but it can broadly activate, send user content to a remote service, and install an additional unpinned workflow skill without review.

Install only if you trust AnyGen and are comfortable sending prompts and files to its servers. Use a narrowly scoped, revocable ANYGEN_API_KEY, avoid regulated or confidential data unless approved, and review or pin both @anygen/cli and anygen-workflow-generate before allowing the secondary skill installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party CLI and Non-Interactive Workflow Skill Installation

Content
View full analysis
-y ``` ``` ### Technical Analysis The project declares `@anygen/cli` without an exact version, immutable package reference, or integrity hash. Package resolution can therefore select a future release that was not part of this audit. The installed CLI is subsequently instructed to install the `anygen-workflow-generate` Skill. This command does not specify an immutable Skill version, source commit, checksum, or signature. The `-y` option additionally permits the installation to proceed without an interactive opportunity to review the resolved source, version, files, and requested behavior. This creates a supply-chain trust chain involving both the npm package and the workflow Skill resolved by that package. If either distribution source, publisher account, package-resolution mechanism, or latest release is compromised, the content executed or loaded by the Agent may differ materially from the reviewed `SKILL.md`. ### Attack Path 1. An attacker compromises the package publisher, registry distribution path, CLI update channel, or remote source used for `anygen-workflow-generate`. 2. The attacker publishes a malicious release under the expected package or Skill identity. 3. The platform resolves the unpinned `@anygen/cli` dependency to the malic ...[truncated 1638 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description contains many broad trigger phrases such as generic requests for making documents, websites, research, data analysis, and images, which can cause the skill to activate for a very wide range of ordinary user intents. Over-broad activation is dangerous because it can route sensitive or unrelated user requests into a third-party content-generation workflow and increase the chance of unintended data disclosure or tool use without clear user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that content is generated server-side at www.anygen.io, but it does not prominently warn that user-provided prompts, documents, or data may be transmitted to a remote service. This creates a meaningful privacy and compliance risk because users may share sensitive business, financial, or personal content without understanding that it leaves the local environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.