Back to skill

Security audit

Agent Auditor

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned, but it asks users to run mutable third-party npm audit code over source trees without version pinning, lockfiles, or integrity controls.

Install only if you are comfortable running third-party npm code over the target source tree. Prefer a pinned, audited package version or lockfile-managed install, and run it in a restricted environment with read-only access to the intended source and no unnecessary secrets or network access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:44
Finding

Unpinned npm Package Is Downloaded and Executed Through npx

Content
View full analysis
``` ### Technical Analysis The documented audit command invokes an npm package without specifying an exact version, integrity hash, or trusted lockfile. Depending on the local npm environment, `npx` can retrieve the currently published package from the configured registry and execute it immediately. Consequently, the code executed by this command can change after the Skill has been reviewed. If the package, publisher account, registry configuration, or dependency chain is compromised, invoking the documented command could run attacker-controlled package code. Package lifecycle scripts and the CLI entry point may execute with the same operating-system privileges as the user or agent running the Skill. The reviewed project does not provide a package manifest, lockfile, vendored implementation, checksum, or other integrity control that establishes which version will execute. This is a supply-chain exposure; the reviewed files do not establish that the current package is malicious. ### Attack Path 1. An attacker compromises the npm publisher account, package, transitive dependency, or registry resolution path for `@claws-shield/cli`. 2. The attacker publishes or serves a modified package version containing malicious lifecycle or CLI code. 3. A user or AI agent follows the command documented in `SKILL.md`. 4. `npx` resolves and potentially downloads the mutable package version. 5. The malicious package executes with the privileges and environment of the invoking process. 6. The package can access files available to that process, including the source tree supplied for auditing, and may access the network if the runtime environment permits it. ### Impact Assessment Successful exploitation can provide arbitrary code execution with the ...[truncated 409 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/run-audit.mjs:3
Finding

Audit Wrapper Delegates Source Access to an Unverifiable External Module

Content
View full analysis
") process.exit(1) } const report = await runAudit(target, { format: "terminal" }) ``` ### Technical Analysis The wrapper imports `runAudit` from `@claws-shield/auditor` and passes it a caller-selected source path. Nearly all substantive audit behavior is therefore implemented by third-party code that is absent from the reviewed project. The project contains no package manifest or lockfile identifying the expected version or integrity value of this module. The wrapper consequently provides no local assurance about which implementation is resolved at runtime. A malicious or compromised installed module can execute during module initialization or when `runAudit` is called. Because the target path is intentionally passed to the dependency for analysis, the dependency receives direct knowledge of a potentially sensitive source location and operates with the wrapper process's filesystem and network permissions. No sandbox, read-only enforcement, network restriction, or dependency authenticity check is implemented by the wrapper. The target path is not validated or canonicalized, but there is no direct command injection in the reviewed wrapper because it does not construct a shell command. The primary confirmed issue is the unverifiable and unrestricted dependency trust boundary. The reviewed source does not prove that `@claws-shield/auditor` itself is malicious. ### Attack Path 1. An attacker causes a malicious implementation of `@claws-shield/auditor` to be installed or resolved, such as through package compromise, registry manipulation, or an untrusted local dependency environment. 2. A user invokes `scr ...[truncated 986 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs users to run npx @claws-shield/cli audit <path-to-source> without pinning an exact package version, which means the executed code can change over time and may resolve to a newly published or compromised release. In a security-audit skill, this is more dangerous than usual because users are encouraged to run third-party code against sensitive source trees, potentially exposing proprietary code or executing attacker-controlled logic.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.