Back to skill

Security audit

open-skills

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real skill-management CLI, but its installer, sync, cleanup, and developer-server behavior can modify or delete important local skill data with insufficient safeguards.

Review before installing. Back up existing Claude/Cursor/Hermes/agent skill directories first, avoid running sync against untrusted or editable registry data, and do not start the developer server on shared or untrusted networks. Prefer waiting for fixes that add path containment, manifest-based cleanup, authentication/CSRF protection, HTML escaping, pinned installer versions, and immutable remote skill revisions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (7)

T09 · Insecure Skill Coding Practices

Error
Location
src/core/cleaner.ts:4
Finding

Recursive cleanup deletes unmanaged and expected Skill files

Content
View full analysis
(); for (const skill of skills) { expectedFiles.add(path.join(skill.name, 'SKILL.md')); } expectedFiles.add('index.md'); await cleanDirectory(targetPath, expectedFiles); } ``` ```ts // src/core/cleaner.ts:4-26 export async function cleanDirectory( targetPath: string, expectedFiles: Set ): Promise { if (!(await pathExistsFn(targetPath))) return; const entries = await readdir(targetPath, { withFileTypes: true }); for (const entry of entries) { const entryPath = path.join(targetPath, entry.name); if (entry.isDirectory()) { await cleanDirectory(entryPath, expectedFiles); const remaining = await readdir(entryPath); if (remaining.length === 0) { await remove(entryPath); } } else { const relative = path.relative(targetPath, entryPath); if (!expectedFiles.has(relative) && !expectedFiles.has(entryPath)) { await remove(entryPath); } } } } ``` ### Technical Analysis The cleanup routine recursively changes `targetPath`, but `expectedFiles` remains relative to the original editor directory. For example, the expected set contains `skill-name/SKILL.md`. After recursion enters `skill-name`, the computed relative path is only `SKILL.md`, so it no longer matches the expected entry and is deleted. The routine also removes every file not present in the current installation set. There is no ownership manifest distinguishing files created by this application from manually installed or third-party Skills. Affected directory presets include: - `~/.claude ...[truncated 1007 chars]
Remediation
View remediation
): Promise { const relative = path.relative(rootPath, entryPath); } ``` 2. Normalize expected and observed paths using one consistent separator and representation. 3. Maintain an application-owned manifest containing only files created by `open-skills`. 4. Delete only files listed in the previous manifest but absent from the new manifest. 5. Never delete unmanaged files automatically. 6. Display a deletion plan and require explicit confirmation before destructive cleanup. 7. Create a backup or move stale files to a recoverable quarantine directory. 8. Add tests for nested Skill directories, unmanaged files, symbolic links, and global installation paths. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/commands/sync.ts:38
Finding

Registry-controlled destination path can empty arbitrary writable directories

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/dev-server/api.ts:6
Finding

Developer server exposes an unauthenticated cross-origin registry modification API

Content
View full analysis
{ return new Promise((resolve) => { const server = http.createServer(async (req, res) => { try { const handled = await handleApi(req, res); if (handled) return; const served = await serveStatic(req, res); if (!served) { res.writeHead(404, { 'Content-Type': 'text/plain' }); res.end('Not Found'); } } catch (err: any) { res.writeHead(500, { 'Content-Type': 'application/json' }); res.end(JSON.stringify({ error: err.message || 'Internal error' })); } }); server.listen(port, () => { console.log(`Developer server running at http://localhost:${port}`); resolve(); }); }); } ``` ```ts // src/cli.ts:18-21 if (args.inc ...[truncated 1818 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/dev-server/web/index.html:245
Finding

Registry metadata is rendered through innerHTML, enabling stored cross-site scripting

Content
View full analysis
${cat.displayName}${count}
编辑删除
`; div.onclick = () => { this.selectedCat = cat.id; this.renderCats(); this.renderSkills(); }; el.appendChild(div); ``` ```js const rows = skills.map((s, idx) => { const globalIdx = this.data.skills.indexOf(s); const tags = (s.tags || []) .map((t) => `${t}`) .join(''); return ` ${s.displayName || s.name}
${s.name}
${s.description} ${s.origin?.type || 'bundle'} ${tags} 编辑删除 `; }).join(''); content.innerHTML = `${rows}
名称描述源Tags操作
`; ``` ### Technical Analysis Values loaded from the writable registry are interpolated directly into HTML strings. Fields including category display names, IDs, Skill names, descriptions, tags, and origin types are not HTML-escaped. A malicious value containing an element with an event handler can execute JavaScript when the panel renders it. Category IDs are additionally embedded inside quoted inline JavaScript, allowing quote termination and script-context injection. Because the registry API accepts cross-origin unauthenticated writes, this vulnerability has a practical remote delivery mechanism whenever the developer server is runn ...[truncated 995 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
bundles/skills/deep-research/scripts/verify_citations.py:151
Finding

Citation verification permits blind server-side requests to internal network targets

Content
View full analysis
Tuple[bool, str]: """ Verify URL is accessible (2025 CiteGuard enhancement). Returns (accessible, status_message) """ if not url: return False, "No URL" try: # HEAD request to check accessibility without downloading req = request.Request(url, method='HEAD') req.add_header( 'User-Agent', 'Mozilla/5.0 (Research Citation Verifier)' ) with request.urlopen(req, timeout=10) as response: if response.status == 200: return True, "URL accessible" else: return False, f"HTTP {response.status}" ``` ```python # verify_citations.py:288-299 # STEP 3: Check URL accessibility (if no DOI or DOI failed) if entry['url'] and result['status'] != 'verified': url_ok, url_status = self.verify_url(entry['url']) if url_ok: result['verification_methods'].append('URL') if result['status'] in ['unknown', 'no_doi', 'unverified']: result['status'] = 'url_verified' print(f" [{entry['num']}] URL accessible ✓") else: result['issues'].append(f"URL check failed: {url_status}") ` ...[truncated 1686 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Installation instructions execute an unpinned third-party package without confirmation

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
src/core/engine.ts:53
Finding

Mutable remote Skill instructions are installed without revision or signature verification

Content
View full analysis
{ const git = simpleGit(); const url = skill.source!.url; const ref = skill.source!.ref || 'main'; const subPath = skill.source!.path; if (!subPath) { const tmpDir = await mkdtemp(path.join(os.tmpdir(), 'open-skills-')); try { await git.clone(url, tmpDir, ['--depth', '1', '--branch', ref]); return await readFile(path.join(tmpDir, 'SKILL.md'), 'utf-8'); } finally { await remove(tmpDir); } } const tmpDir = await mkdtemp(path.join(os.tmpdir(), 'open-skills-')); try { await git.clone(url, tmpDir, [ '--depth', '1', '--branch', ref, '--no-checkout' ]); const repoGit = simpleGit(tmpDir); await repoGit.raw(['sparse-checkout', 'init', '--cone']); await repoGit.raw(['sparse-checkout', 'set', subPath]); await repoGit.checkout(ref); return await readFile(path.join(tmpDir, subPath, 'SKILL.md'), 'utf-8'); } finally { await remove(tmpDir); } } ``` ```json // registry/skills.json:82-90 { "name": "andrej-karpathy-skills", "displayName": "andrej-karpathy-skills", "origin": { "type": "github", "ref": "forrestchang/andrej-karpathy-skills", "url": "https://github.com/forrestchang/andrej-karpathy-skills.git" }, "version": "main" } ``` ### Technical Analysis The engine clones a branch or tag supplied by registry metadata, defaulting to `main`. Branch names are mutable references, so the downloaded `SKILL.md` can change after registry review. The downloaded instruction file is accepted without: - An immutable commit hash - A content digest - Signed-commit or signed-tag verification - A trusted-publisher policy - User-visible diff re ...[truncated 1325 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (166)

Known Vulnerable Dependency: vitest==3.2.4 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vitest==3.2.4 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
95% confidence
Finding

The manifest allows Vitest 3.2.4 via the caret range, and that version is reported as having critical advisories including arbitrary file read and possible code execution when the Vitest UI server is exposed. Although Vitest is only a devDependency, exploitation can still affect developers or CI environments that run tests or start the UI, so the skill context makes this less dangerous than a runtime production dependency but still a real supply-chain risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The repeated description-behavior mismatch findings indicate that the published skill metadata does not accurately represent the underlying functionality. When a skill claims to be a benign interactive installer but actually performs unrelated network, file, registry, validation, server, or research-oriented actions, users cannot meaningfully assess risk and may authorize actions they did not intend.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · bundles/skills/deep-research/ARCHITECTURE_REVIEW.md (reported line 381)May include surrounding context.

text

**2. Conditional REFINE Phase**
Update SKILL.md and research_engine.py:
```python
def get_phases_for_mode(mode: ResearchMode) -> List[ResearchPhase]:
    if mode == ResearchMode.QUICK:

Static analysis

No suspicious patterns detected.