Back to skill

Security audit

pretext

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real text-layout utility, but it also generates active browser HTML/JavaScript with unsafe interpolation and an unpinned CDN dependency, so users should review it before installing.

Install only if you need this broader frontend helper, not just passive text measurement. Avoid pasting its generated snippets into authenticated or sensitive pages, pin or vendor the browser dependency instead of using the unversioned CDN URL, and treat generated HTML/JavaScript as untrusted when any input text or styling options come from another user.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/particle-text.js:105
Finding

Stored JavaScript Injection in Generated Particle Animation HTML

Content
View full analysis
\n'; html += '\n\n'; // ... html += '` can terminate the enclosing script element before JavaScript parsing occurs. The attacker can then append a new script element or arbitrary HTML. The defined `escapeHtml()` function is not applied to the serialized particle data. Even if it were applied naively, HTML escaping would need to be designed specifically for data embedded inside an executable script. ### Attack Path 1. An attacker provides crafted text containing an HTML script termination sequence, such as a value based on: ```text ``` 2. The victim or an automated agent runs: ```bash node scripts/particle-text.js --text "" ``` 3. The script creates `particle-text-demo.html` in the project directory. 4. The victim opens the generated file as directed by the documentation. 5. The browser's HTML parser terminates the original script at the injected `` sequ ...[truncated 779 chars]
Remediation
View remediation
/g, '\\u003e') .replace(/&/g, '\\u0026') .replace(/\u2028/g, '\\u2028') .replace(/\u2029/g, '\\u2029'); } const particlesJson = serializeForInlineScript(particles); ``` 3. Prefer placing serialized data in a non-executable JSON element and reading it safely: ```html ``` The JSON content must still encode `<` as `\u003c` to prevent HTML parser termination. 4. Better still, generate the document using a trusted templating system with context-aware escaping. 5. Add tests containing ``, `

T09 · Insecure Skill Coding Practices

Error
Location
scripts/measure-browser.js:68
Finding

JavaScript Injection in Generated Browser Measurement Snippet

Content
View full analysis
<\/script> ` inside script content regardless of whether it appears within a JavaScript string literal. Therefore, crafted input can terminate the legitimate script and introduce attacker-controlled markup or a second script. The documentation explicitly encourages use of the generated snippet in a browser, making the injection path part of the intended workflow. ### Attack Path 1. An attacker supplies a crafted `--text` value containing a script-closing sequence and an attacker-controlled script element. 2. The victim runs: ```bash node scripts/measure-browser.js \ --text "" \ --output snippet ``` 3. The tool emits an apparently legitimate Pretext HTML snippet. 4. The victim pastes or inserts the snippet into an HTML document as documented. 5. The injected `` terminates the intended script. 6. The attacker's script executes under the origin of the document receiving the snippet. ### Impact Assessment Exploitation provides arbitrary JavaScript execution in the consuming page's origin. This may allow an attacker to: - Read DOM content and application state. - Access non-HttpOnly tokens or ...[truncated 337 chars]
Remediation
View remediation
/g, '\\u003e') .replace(/&/g, '\\u0026') .replace(/\u2028/g, '\\u2028') .replace(/\u2029/g, '\\u2029'); } ``` 3. Use `safeScriptJson(text)` instead of raw `JSON.stringify(text)`. 4. Prefer generating JavaScript-only output for execution in a trusted console rather than an HTML snippet. 5. If HTML output is required, place user data in an inert DOM node and retrieve it using `textContent`. 6. Add regression tests using script-closing sequences and Unicode line separators. 7. Recommend a restrictive Content Security Policy without `unsafe-inline`. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render-dom.js:96
Finding

HTML Attribute and CSS Injection in DOM Rendering Output

Content
View full analysis
{ const w = estimateWidth(line, fontSize); const alignStyle = align === 'justify' ? 'text-align:justify' : `text-align:${align}`; const rpad = align === 'left' || align === 'justify' ? '' : `padding-right:${width - w}px`; return ` <${tagName} class="${lineClass}" data-line="${i}" style="height:${lineHeight}px;line-height:${lineHeight}px;font:${font};${alignStyle};${rpad}overflow:hidden;white-space:nowrap;">${escapeHtml(line)}`; }); const containerHtml = `<${tagName} id="${containerId}" class="pretext-rendered" style="width:${width}px;font:${font};overflow:hidden;"> ${lineHtmls.join('\n')} `; const css = `.pretext-rendered { position:relative; overflow:hidden; } .${lineClass} { width:${width}px; box-sizing:border-box; } `; return { // ... browserSnippet: `${css} ${containerHtml}
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/layout-lines.js:153
Finding

JavaScript Code Injection in Generated Canvas Drawing Code

Content
View full analysis
`ctx.fillText('${l.text.replace(/'/g, "\\'")}', 0, ${l.y});`).join('\n')}` ``` ### Technical Analysis The generated `canvasCode` is executable JavaScript intended for reuse by consumers. Text values are protected only by replacing apostrophes with `\'`. This is not sufficient JavaScript-string encoding. For example, attacker-controlled backslashes can alter how the inserted escape sequence is interpreted. JavaScript line terminators and Unicode line-separator characters can also break the generated string or change the resulting source structure. The `font` value is inserted without any escaping at all. Manual replacement of one quote character does not provide safe JavaScript source serialization. ### Attack Path 1. An attacker supplies crafted text or a crafted font value. 2. `layout-lines.js` generates `canvasCode` containing the attacker-controlled value. 3. A developer, agent, or application executes the generated code as intended. 4. The crafted value escapes or alters the generated JavaScript string context. 5. Attacker-controlled JavaScript runs with the privileges of the execution environment. ### Impact Assessment The immediate impact is arbitrary code execution in whichever JavaScript environment evaluates the generated Canvas code. - In a browser, this grants access to the hosting page's DOM and origin-level script privileges. - In Node.js or an Electron-like environment, the impact may include filesystem and process access if those capabilities are available to the evaluator. - The vulnerability does not execute automatically during normal JSON generation; exploitation requires a consumer to execute the emitted ...[truncated 9 chars]
Remediation
View remediation
`ctx.fillText(${JSON.stringify(line.text)}, 0, ${Number(line.y)});` ); const canvasCode = [ `const ctx = canvas.getContext('2d');`, `ctx.font = ${safeFont};`, ...drawingLines, ].join('\n'); ``` 2. Verify every coordinate with `Number.isFinite()` before source generation. 3. Prefer returning structured data rather than executable source code. 4. If code output remains supported, document that consumers must not evaluate untrusted output. 5. Add regression tests for backslashes, apostrophes, CR/LF, U+2028, U+2029, and mixed escape sequences. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wrap-layout.js:116
Finding

JavaScript Code Injection in Generated Wrapped-Layout Canvas Code

Content
View full analysis
`ctx.fillText('${l.text.replace(/'/g, "\\'")}', ${l.x}, ${l.y});`).join('\n')}`, ``` ### Technical Analysis The generated Canvas program embeds text and font values directly into JavaScript string literals. Text handling only escapes apostrophes, while the font value is not escaped. This does not safely handle backslashes, JavaScript line terminators, Unicode line separators, or combinations where an attacker-controlled backslash changes the meaning of the inserted apostrophe escape. The resulting `canvasCode` is therefore unsafe to execute when any embedded value is attacker-controlled. ### Attack Path 1. An attacker controls the measured text or font value. 2. The attacker includes characters designed to break or alter the generated JavaScript string. 3. `wrap-layout.js` returns the generated `canvasCode`. 4. A consumer copies, evaluates, or otherwise executes that code. 5. The attacker's JavaScript executes in the consumer's runtime. ### Impact Assessment The attacker obtains the privileges available to the JavaScript runtime that executes the generated source: - Browser DOM access and same-origin script capabilities in a web page. - Potential local filesystem or process access in Node.js, Electron, or other privileged runtimes. - Ability to alter the generated drawing behavior or falsify layout output. Execution requires a downstream consumer to run the generated code, so the issue is not an automatic local command-execution path in the Skill itself. ]]>
Remediation
View remediation
{ if (!Number.isFinite(line.x) || !Number.isFinite(line.y)) { throw new Error('Invalid Canvas coordinates'); } return `ctx.fillText(${JSON.stringify(line.text)}, ${line.x}, ${line.y});`; }).join('\n'); ``` 2. Serialize the font value using `JSON.stringify(font)`. 3. Validate `floatSide` against an explicit allowlist before including it in generated output. 4. Prefer returning a JSON drawing plan instead of executable code. 5. Add security tests covering escape-sequence combinations and Unicode line separators. ]]>

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/measure-browser.js:68
Finding

Mutable Remote Browser Payload Loaded Without Version Pinning or Integrity Verification

Content
View full analysis
<\/script>
Remediation
View remediation
``` 2. Add Subresource Integrity and CORS metadata using a hash calculated from the exact pinned artifact: ```html ``` 3. Prefer bundling a reviewed copy of the dependency locally with the Skill or application. 4. Maintain a lockfile and verify package checksums during installation and release. 5. Update both generated output and all documentation so users are not directed to an unversioned CDN path. 6. Review and deliberately update the pinned version and integrity hash through a controlled dependency-update process. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents the skill as a text measurement/layout engine used to compute text height, wrapping, and layout. However, the supplied code chunk does not perform any text measurement or layout calculation at all. Its primary purpose is operational maintenance: clearing Pretext's internal cache via a CLI script. That is materially different from the declared end-user functionality. While cache management may support a text measurement engine, this code chunk itself implements only cache clearing and installation/error handling, which is not accurately represented by the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明的核心能力是“精准文本测量与布局”,强调纯算术计算文本像素高度、换行行数和布局预计算,不触碰 DOM。实际代码虽然包含非常粗略的字符宽度估算、简单逐字符换行和行数统计,但这些只是为粒子动画排版提供辅助。代码的主要目的明显是生成一个可视化的 Canvas 粒子文字动画 HTML 页面,并支持鼠标交互、反弹/环绕、重力、爆炸、打字机等效果。此外,代码会使用文件系统将 HTML 写入磁盘,这与声明的无权限、纯计算型布局引擎不符。因此这是实质性描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description emphasizes a non-DOM, pure-calculation text measurement engine whose purpose is to compute pixel height, wrapping, and layout metrics. The supplied code materially goes beyond that and in fact centers on DOM rendering. Its header explicitly says it renders Pretext measurement results to real DOM elements. The main exported function renderToDOM builds HTML strings, CSS, and a browser snippet containing <script> code with mouse event listeners and per-character animation. Additional functions generate ready-to-render accordion and chat bubble HTML. While the code reuses arithmetic text measurement as a supporting mechanism, the primary behavior of this chunk is UI/DOM generation, which directly conflicts with the claim '无需触碰 DOM' ('no need to touch the DOM'). Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

该描述与代码存在实质不匹配。描述强调的是一个“精准文本测量与布局引擎”,核心能力是纯算术地计算文本像素高度、换行行数和精确布局,且特别声称“无需触碰 DOM”“基于开源 Pretext”。但代码的主功能其实是“文本围绕浮动元素排版”:根据 floatWidth/floatHeight/floatSide 计算每行可用宽度,输出每行的 x/y 坐标和绕排结果。这比声明的普通文本高度测量更具体,也属于未声明的主要能力扩展。其次,代码确实会设置 global.document 并在可用时创建 canvas,对“无需触碰 DOM”的表述构成直接冲突。再次,虽然尝试 require Pretext,但实际核心算法没有调用其排版能力,而是使用自定义 unicodeCharWidth 近似估算字符宽度;因此“基于 Pretext”“精准像素高度”也有夸大之嫌。综合看,代码不是恶意或越权资源访问,但其主要用途、实现方式和声明均有明显偏差,应判定为不匹配。

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The script invokes child processes with execSync and explicitly forwards the entire parent environment via env: { ...process.env }. That exposes secrets such as npm tokens, proxy credentials, or other sensitive environment variables to all install-time subprocesses and package lifecycle scripts, which is risky because npm install executes third-party code during installation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata describes a pure text measurement/layout engine, but this code generates a browser-executed interactive HTML particle demo instead. That mismatch expands behavior beyond the declared scope and causes untrusted input such as text, colors, and wrap mode to be embedded into generated HTML/JavaScript, increasing the attack surface and violating least functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file goes beyond passive text measurement and generates executable HTML/JavaScript snippets for browser insertion, including a browserSnippet that attaches event listeners and mutates DOM content. In a skill advertised as pure arithmetic layout without touching the DOM, this scope expansion increases the chance that downstream consumers will paste active code into privileged browser contexts, creating an unnecessary script injection surface even though text content itself is HTML-escaped.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description and usage guidance are presented entirely in Chinese, which imposes a specific language on users without an explicit opt-in or alternative locale. The policy allows locale constraints only when justified or when users are given a choice, neither of which is stated here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description frames the skill as a pure text measurement/layout engine that computes height and line count without touching the DOM. However, the documented capabilities include generating HTML snippets via render-dom.js and later advising agents to generate browser-injectable code, which expands the skill from measurement into UI rendering/output generation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The stated purpose is precise text measurement, line wrapping, and layout precomputation. The particle-text feature generates interactive Canvas animations with physics-like behaviors, mouse interaction, gravity, explosions, and typing effects, which is materially broader than measurement/layout.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation explicitly encourages generation of browser-injectable code snippets. In an agent context, code injection helpers can be repurposed to emit active content that gets pasted into a browser or page context, blurring the line between measurement and script execution and increasing the risk of XSS-style misuse or unsafe automation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s descriptive header presents the skill name only in Chinese, and later user-facing output strings are also Chinese-only. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

When required arguments are missing, the script emits user-facing guidance exclusively in Chinese. Because the file does not offer language selection or explain a justified locale restriction, this conflicts with the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file presents its title, status messages, warnings, and usage guidance primarily in Chinese, including all user-facing console output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install-deps.js (reported line 69)May include surrounding context.

js
console.warn('\n⚠️  canvas 安装失败(Cairo 系统库未安装)');
  console.warn('   Skill 已内置纯 JS fallback,仍可正常工作');
  console.warn('   如需 canvas:');
  console.warn('   Linux:  sudo apt install libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev');
  console.warn('   macOS:  brew install pkg-config cairo pango jpeg giflib librsvg\n');
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The header comments and usage instructions are entirely in Chinese, and the script's user-facing console messages and JSON description are also Chinese-only. This imposes a specific language on users without opt-in or documented justification, which matches the locale/language policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script generates browser code that instructs consumers to load and execute a remote script from unpkg at runtime. That creates a supply-chain and integrity risk inconsistent with the stated local measurement-only purpose, because whoever controls or tampers with the CDN response can run arbitrary JavaScript in the target browser context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Although the skill is described as a text measurement utility, the generated snippet expands its capability to fetch external code over the network and execute it in-page. In an agent setting, this broadens trust boundaries and can expose browser sessions, page data, or tokens if the external dependency is compromised or swapped.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The emitted HTML snippet directly includes a remote

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains user-facing and instructional natural language exclusively in Chinese, including the header description and later runtime messages. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code includes browser-interactive animation logic, mouse tracking, click handlers, gravity, explosion, and typewriter effects that are unrelated to pure arithmetic text measurement. In this skill context, those capabilities are unjustified and dangerous because they create active client-side behavior and enlarge the surface for injection, misuse, and unexpected side effects when the generated HTML is opened.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI presents itself as a particle motion engine rather than the declared text layout utility, confirming a scope mismatch between advertised capability and actual implementation. While this is not direct code execution by itself, such deceptive or misleading functionality can cause the agent or users to invoke a broader-capability tool than intended, undermining trust boundaries and review assumptions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Writing a standalone HTML file to disk is outside the expected behavior of a pure computation skill and can introduce persistence and follow-on execution risk if downstream systems automatically open or serve the file. In this codebase, the written HTML contains embedded script and user-influenced values, making the disk write materially more risky than a simple report output.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The browserSnippet contains interactive client-side scripting that rewrites innerHTML and binds mouseenter/mouseleave handlers to all generated line elements. That is not required for text measurement and creates avoidable active behavior that a caller may embed or execute, broadening the attack surface and violating least functionality for the skill's stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The renderAccordion and renderChatBubbles functions build complete UI component HTML, styles, and interaction hooks for accordion and chat bubble presentations. While these use layout calculations, shipping full component rendering is a broader presentation capability than the manifest's stated role of text measurement and layout precomputation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install-deps.js:41

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/test-compare.js:25

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/test-zh-en.js:20