Back to skill

Security audit

better-design

Security checks for vulnerabilities and agentic risk

Overview

This design helper is mostly purpose-aligned, but it tells agents to connect to a remote service and run an install command returned by that service without clear command limits or user approval.

Install only if you are comfortable using Better Design as a remote design provider. Before any React or Next.js install, require the agent to show the exact command, package sources, destination paths, and files to be changed, and approve it only if it matches your project. Avoid sending private source, fixtures, or unreleased product details unless your account and provider terms are acceptable for that data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:51
Finding

Remote MCP Response Supplies a Command for Local Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 51–55
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Instruction

markdown
Call `get-design-system-kit` with the target that fits the project:

| Project | Target |
| --- | --- |
| React or Next.js with a terminal | `react`, then run the returned install command |

Technical Analysis

When installing a design system into a React or Next.js project, the Skill instructs the agent to call get-design-system-kit on the remote Better Design MCP server and execute the installation command returned by that service.

The returned command is external service data, but the instruction provides no technical control that restricts its executable, arguments, download source, shell syntax, or affected paths. It also does not require the exact command to be shown to and explicitly approved by the user before execution.

This creates a direct trust transition from a remotely controlled MCP response to local command execution. The project contains no evidence that the service currently returns a malicious command, so this is a reachable high-risk behavior rather than proof of malicious intent.

Attack Path

  1. A user asks the agent to install a Better Design system in a React or Next.js project.
  2. The agent connects to https://better-design.com/api/mcp.
  3. The agent calls the remote get-design-system-kit tool with the react target.
  4. The remote service supplies an installation command.
  5. Following SKILL.md, the agent runs that command in the local terminal without an allowlist, integrity check, or mandatory user approval.
  6. If the MCP service or its response channel is malicious or compromised, the returned command executes with the agent process's local privileges.

Impact Assessment

A malicious returned command could execute arbitrary code with the privileges available to the agent. Depending on the runtime environment, this could ...[truncated 500 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace execution of an opaque server-returned command with a fixed, locally defined installer and a strict allowlist of supported package managers and arguments.
  2. Treat every returned command as untrusted data and parse it without invoking a shell.
  3. Display the complete command, download sources, package names, versions, and destination paths to the user, then require explicit approval before execution.
  4. Reject shell metacharacters, redirections, pipelines, command substitutions, environment assignments, unexpected executables, and unapproved URLs.
  5. Pin dependency versions and verify downloaded artifacts using trusted signatures or cryptographic hashes where supported.
  6. Run installation with the minimum necessary privileges and prohibit elevation unless separately justified and approved.
  7. Prefer returning declarative installation metadata—such as package names, versions, and file manifests—rather than executable command text.
  8. Validate that all filesystem changes remain within the user-selected project directory.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance is broad enough to trigger on many common UI, app, site, or component requests, causing the agent to connect to and rely on a third-party remote MCP server more often than necessary. This expands the attack surface and can lead to unnecessary external data sharing or tool use in contexts where the user did not explicitly request Better Design integration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.