Back to skill

Security audit

Agentsec

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it repeatedly tells users to execute and globally install an unpinned npm CLI that will scan local skill directories.

Review before installing in sensitive environments. Prefer a pinned agentsec version, a lockfile-managed local install, or an internally vetted package mirror, and run targeted scans with --path or --platform when you do not want all default skill directories inspected.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Third-Party npm Package Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–29 and 48–55
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

yaml
install:
  - kind: node
    package: agentsec
    bins:
      - agentsec
    label: Install agentsec (npm)
markdown
The fastest path to a result — no install, no flags:

```bash
npx agentsec

This scans every default skills directory on the machine — grouped by platform — plus any ./skills folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.

text

The document also recommends persistent global installation at lines 89–99:

```bash
# bun (recommended)
bun add -g agentsec

# npm
npm install -g agentsec

# pnpm
pnpm add -g agentsec

# yarn
yarn global add agentsec

Technical Analysis

The skill directs users or agents to retrieve and execute the agentsec npm package without pinning an exact audited version or supplying a lockfile, integrity hash, signature, or immutable source reference. Depending on local npx behavior and cache state, npx agentsec can download and execute the package version currently selected by the registry.

Consequently, the code ultimately executed may differ from the artifact that was reviewed. Package lifecycle scripts and the CLI itself can execute with the privileges of the invoking user. The globally installed alternatives increase persistence and can expose subsequent invocations to a compromised release.

This is a supply-chain risk rather than evidence that the current agentsec package is malicious. The reviewed project contains no bundled executable implementation with which to verify the package’s behavior.

Attack Path

  1. An attacker compromises the npm package publisher, registry release process, or a transitive dependency used by a future package release.
  2. The attacker publishes a malicious version that ...[truncated 1125 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an exact reviewed version in all examples, such as npx --yes agentsec@<exact-version>, and update the pin only after review.
  2. Use a project-local dependency with a committed lockfile rather than encouraging unversioned, on-demand execution.
  3. Verify package provenance and registry integrity metadata. Where supported, require signed provenance and validate the expected package publisher.
  4. Use deterministic package-manager settings and integrity-checked caches in CI.
  5. Disable dependency lifecycle scripts where operationally feasible, or inspect all required lifecycle scripts before installation.
  6. Execute the scanner in a sandbox or isolated CI job with read-only repository access, a minimal environment, no unrelated secrets, and no unnecessary network or filesystem permissions.
  7. Avoid global installation in security-sensitive environments. If it is necessary, pin the exact version and document a controlled update and rollback procedure.
  8. Document the expected package identity, version, checksum or integrity value, and verification procedure directly in the skill.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
low ships skills in the [agentskills.io](https://agentskills.io/specification) `SKILL.md` format and is auto-discovered.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quick-start encourages users to run the tool immediately and only afterward mentions that it scans default skill directories across the machine and nearby project folders. This lacks a prominent warning about scope and privacy implications, so users may unknowingly inventory sensitive local paths or organizational skill repositories.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The quick-start instructs users to run npx agentsec without pinning a package version. This creates a supply-chain risk because execution depends on whatever version is current in the registry at runtime, allowing unexpected behavior or a compromised release to be fetched and executed.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
agentsec is agent-platform agnostic — every platform listed below ships skills in the [agentskills.io](https://agentskills.io/specification) `SKILL.md` format and is auto-discovered.

| Platform               | Paths scanned                                                                                                             |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |
| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This command example uses npx agentsec without a pinned version, so users may execute an unintended or newly compromised package version. In a security-auditing skill, encouraging unpinned runtime package fetches is especially risky because users are likely to trust and run these commands in sensitive environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The documentation recommends npx agentsec scan without version pinning, which permits registry drift and supply-chain substitution at execution time. If the package is tampered with upstream, users could run attacker-controlled code while believing they are performing a security scan.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The report-generation example still invokes npx agentsec without a pinned version. This leaves execution dependent on the latest registry state and can introduce malicious or breaking changes into otherwise offline reporting workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The policy-management example references npx agentsec without constraining the version. Unpinned package execution is a classic supply-chain risk and is inappropriate guidance in a security-focused skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The installation section states that npx agentsec needs no install, but omits version pinning. That promotes convenience over integrity and can normalize executing transient registry content directly on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The verbose-mode example uses unpinned npx agentsec, exposing users to registry drift and potential malicious package delivery. Because verbose scans may be run on broad local skill inventories, compromise could expose a large amount of local metadata.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The directory-scan recipe uses npx agentsec scan --path ./my-skills without version pinning. That makes security-sensitive scanning behavior depend on the latest package served by the registry rather than a reviewed release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This platform-targeting example invokes npx agentsec without pinning the package version. An attacker controlling or compromising the upstream package could gain code execution on hosts where users run this command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The codex platform example continues the same unpinned npx pattern, allowing execution of whatever package version is current at runtime. This is a supply-chain weakness, not just a style issue, because the command directly executes fetched code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The hermes platform example is also unpinned and therefore vulnerable to upstream package drift or compromise. Repeating this pattern throughout the skill increases the likelihood users adopt unsafe execution habits.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The openclaw platform example recommends unpinned npx execution. In a security context, this can undermine trust in the very audit process by allowing the auditing tool itself to be substituted or altered.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The strict-policy JSON output recipe still fetches and executes the latest agentsec version via npx. In CI/CD, this can create non-reproducible builds and expose pipelines to supply-chain attacks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The HTML report recipe uses unpinned runtime package execution. If the package changes unexpectedly, generated artifacts may be altered or malicious behavior introduced during report generation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The SARIF generation example relies on unpinned npx execution, which is risky in IDE and code-scanning integrations where output may drive downstream security workflows. A compromised release could falsify or manipulate security results.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The policy listing example again uses unpinned npx, preserving the same package substitution risk. Even seemingly harmless inspection commands execute package code and should be treated as code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The preset-inspection example uses unpinned package execution, allowing upstream drift to affect local command behavior. This is particularly problematic in a tool positioned as a governance and policy aid.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The policy validation example still executes the latest package version via npx. In automation or pre-commit hooks, this creates both reliability and supply-chain security concerns.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The replay-report example uses unpinned npx, so even post-processing of an existing audit depends on an unreviewed latest package. That undermines reproducibility and can introduce malicious behavior in environments where reports are handled.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The Web3 profile example invokes npx agentsec audit --profile web3 without version pinning. In Web3-adjacent contexts, tool compromise is especially sensitive because findings may influence signing, wallet, or deployment decisions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The CI gating example npx agentsec --policy strict || exit 1 is unpinned, which is especially dangerous in CI because it grants transient registry content control over build results and execution. An attacker could cause false passes, false failures, or direct code execution in the pipeline.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.