Back to skill

Security audit

vx-best-practices

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent vx guidance, but it includes raw migration commands that recursively delete user tool-manager directories without safety checks.

Review this skill before installing if you let agents run migration commands. The vx setup guidance is generally purpose-aligned, but do not allow automatic execution of the nvm or pyenv removal commands unless you have confirmed the directory contents are no longer needed and have backups where appropriate.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

Never commit secrets. Use environment variables:

bash
# .env (add to .gitignore)
DATABASE_URL=postgresql://...
API_KEY=secret123

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding is the same unsafe deletion command, specifically matched as 'rm -rf ~/.nvm'. While likely intended as cleanup, it still normalizes a high-risk destructive pattern in a skill document that may be acted on automatically.

Content

Scanner excerpt · SKILL.md (reported line 445)May include surrounding context.

vx add node@$(cat .nvmrc | tr -d 'v')

4. Remove nvm

rm -rf ~/.nvm

text

### From pyenv → vx

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding is the same unsafe deletion command, specifically matched as 'rm -rf ~/.nvm'. While likely intended as cleanup, it still normalizes a high-risk destructive pattern in a skill document that may be acted on automatically.

Content

Scanner excerpt · SKILL.md (reported line 445)May include surrounding context.

vx add node@$(cat .nvmrc | tr -d 'v')

4. Remove nvm

rm -rf ~/.nvm

text

### From pyenv → vx

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding is the same unsafe deletion command, specifically matched as 'rm -rf ~/.pyenv'. The risk is accidental destructive action rather than code execution, but in agent-facing documentation that is still a meaningful safety issue.

Content

Scanner excerpt · SKILL.md (reported line 461)May include surrounding context.

vx add uv

4. Remove pyenv

rm -rf ~/.pyenv

text

## Provider Development Best Practices

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding is the same unsafe deletion command, specifically matched as 'rm -rf ~/.pyenv'. The risk is accidental destructive action rather than code execution, but in agent-facing documentation that is still a meaningful safety issue.

Content

Scanner excerpt · SKILL.md (reported line 461)May include surrounding context.

vx add uv

4. Remove pyenv

rm -rf ~/.pyenv

text

## Provider Development Best Practices

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

toml
[env]
NODE_ENV = "development"
DEBUG = "app:*"

# Required variables (vx will warn if missing)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 301)May include surrounding context.

bash
# Install as regular user, not root
# ❌ sudo vx install node

# vx manages user-level installations
vx install node

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 454)May include surrounding context.

md
# 1. Check current Python version
python --version

# 2. Create vx.toml
vx init

# 3. Add uv (recommended Python manager)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.