Back to skill

Security audit

NEAR Content Creator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent NEAR content generator that makes fixed public data requests, with dependency hygiene notes but no evidence of hidden data access or destructive behavior.

Reasonable to install for NEAR content generation if you are comfortable with it contacting public market, chain, news, and GitHub endpoints. Before using it in development or CI, update the flagged dev dependencies, keep dev servers bound to trusted interfaces, and review the build step because the package points to dist/index.js but ships source that must be built.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Known Vulnerable Dependency: vitest==4.0.18 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
96% confidence
Finding

vitest 4.0.18 is flagged for arbitrary file read and possible execution when the Vitest UI server is listening, plus the @vitest/mocker traversal issue. In this repository Vitest is only for testing, but if its UI/server features are enabled in development or CI and reachable by untrusted parties, an attacker could access sensitive files or trigger code execution paths.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vitest==4.0.18 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

The project includes vitest 4.0.18, which is flagged with critical advisories for arbitrary file read and code execution when the Vitest UI server is listening, and for path traversal/arbitrary file read via mocker redirect behavior. Although vitest is a dev dependency, exploitation could seriously impact developer machines or CI systems if the vulnerable test infrastructure is run, making this especially dangerous in environments that expose the UI server or process untrusted test inputs.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
91% confidence
Finding

form-data 4.0.5 is flagged for CRLF injection via unescaped multipart field names/values. In this project it is only pulled in through @types/node-fetch as a dev dependency chain, which makes direct exploitability less likely, but if any tooling or scripts construct multipart requests from untrusted input the bug could enable header/body manipulation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
81% confidence
Finding

nanoid 3.3.11 is associated with denial-of-service style issues such as infinite loops or integer wraparound in edge-case generator usage. In this lockfile it is a transitive dev dependency via PostCSS/Vite, so the main risk is build/dev process instability if attacker-controlled parameters reach the generator, not obvious production compromise.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: picomatch==4.0.3 — 2 advisory(ies): CVE-2026-33672 (Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Mat); CVE-2026-33671 (Picomatch has a ReDoS vulnerability via extglob quantifiers)

High
Category
Supply Chain
Confidence
90% confidence
Finding

picomatch 4.0.3 is reported vulnerable to ReDoS and method-injection-style glob parsing issues. Because it is used by Vite/Vitest tooling, maliciously crafted glob patterns or paths in a development/testing context could cause excessive resource consumption or incorrect matching behavior.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.6 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

postcss 8.5.6 is flagged for multiple issues including arbitrary file read/information disclosure and XSS-related output handling. In this package it is a dev dependency via Vite, so the danger is mostly during local/CI asset processing rather than the NEAR content skill's core runtime, but it still matters if untrusted CSS or sourcemap data is processed.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: rollup==4.58.0 — 1 advisory(ies): CVE-2026-27606 (Rollup 4 has Arbitrary File Write via Path Traversal)

High
Category
Supply Chain
Confidence
89% confidence
Finding

rollup 4.58.0 is flagged for arbitrary file write via path traversal. As a build-time dependency, exploitation would generally require an attacker to influence build inputs, plugin behavior, or artifact paths; this makes it less dangerous than a runtime vulnerability but still important in CI or shared development environments.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vite==7.3.1 — 5 advisory(ies): CVE-2026-39365 (Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling); CVE-2026-53571 (vite: `server.fs.deny` bypass on Windows alternate paths); CVE-2026-39363 (Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket) +2 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

vite 7.3.1 is flagged for multiple path traversal and arbitrary file read issues in the dev server. Even though Vite is a dev dependency, these issues can expose local files or bypass filesystem restrictions when the dev server is running, which is significant for developer workstations and CI agents.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises an implementation entrypoint and the analyzer detected network-capable code, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: a caller may invoke a content-generation skill without realizing it can access external resources, which can lead to unintended outbound requests, data exposure, or retrieval of untrusted content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/content-creator.ts (reported line 4)May include surrounding context.

ts
import fetch from 'node-fetch';

const COINGECKO_NEAR =
  'https://api.coingecko.com/api/v3/simple/price?ids=near&vs_currencies=usd&include_24hr_change=true&include_market_cap=true&include_24hr_vol=true';
const NEAR_RPC = 'https://rpc.mainnet.near.org';
const NEARBLOCKS_STATS = 'https://api.nearblocks.io/v1/stats';
const THREAD_POST_COUNT = 8;

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/content-creator.ts (reported line 6)May include surrounding context.

ts
const COINGECKO_NEAR =
  'https://api.coingecko.com/api/v3/simple/price?ids=near&vs_currencies=usd&include_24hr_change=true&include_market_cap=true&include_24hr_vol=true';
const NEAR_RPC = 'https://rpc.mainnet.near.org';
const NEARBLOCKS_STATS = 'https://api.nearblocks.io/v1/stats';
const THREAD_POST_COUNT = 8;
const MAX_THREAD_POST_LEN = 280;
const NEWS_MAX_ITEMS = 12;

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/content-creator.ts (reported line 170)May include surrounding context.

ts
async function collectGithubReleaseNews(): Promise<NewsItem[]> {
  const endpoints: Array<{ source: string; url: string }> = [
    { source: 'near/nearcore releases', url: 'https://api.github.com/repos/near/nearcore/releases?per_page=3' },
    {
      source: 'near/near-api-js releases',
      url: 'https://api.github.com/repos/near/near-api-js/releases?per_page=3'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/content-creator.ts (reported line 173)May include surrounding context.

ts
async function collectGithubReleaseNews(): Promise<NewsItem[]> {
  const endpoints: Array<{ source: string; url: string }> = [
    { source: 'near/nearcore releases', url: 'https://api.github.com/repos/near/nearcore/releases?per_page=3' },
    {
      source: 'near/near-api-js releases',
      url: 'https://api.github.com/repos/near/near-api-js/releases?per_page=3'

Known Vulnerable Dependency: @vitest/mocker==4.0.18 — 1 advisory(ies): CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Low
Category
Supply Chain
Confidence
93% confidence
Finding

@vitest/mocker 4.0.18 is flagged for a path traversal/arbitrary file read issue in Vitest mock redirection. In this lockfile it is only a dev/test dependency, so exploitation would typically require running the test tooling in a context where untrusted inputs or test artifacts are processed; that reduces but does not eliminate risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: esbuild==0.27.3 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
85% confidence
Finding

esbuild 0.27.3 is reported vulnerable to arbitrary file read when its development server is used on Windows. Here it appears as a transitive dev dependency through Vite/Vitest, so the issue is relevant mainly during local development or CI on Windows rather than in the skill's runtime behavior.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The production dependency node-fetch is specified with a caret range, which allows automatic installation of newer minor/patch releases instead of a single audited version. This increases supply-chain risk because builds are not fully reproducible and a compromised or breaking upstream release could be pulled in without explicit review.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"author": "mastrophot",
  "license": "MIT",
  "dependencies": {
    "node-fetch": "^2.7.0"
  },
  "devDependencies": {
    "@types/node": "^24.3.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
84% confidence
Finding

@types/node is unpinned via a caret range, so different installs may resolve to different versions over time. While this is a development-only package, it still weakens build reproducibility and introduces some supply-chain exposure in CI or developer environments.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
"node-fetch": "^2.7.0"
  },
  "devDependencies": {
    "@types/node": "^24.3.0",
    "@types/node-fetch": "^2.6.13",
    "typescript": "^5.9.2",
    "vitest": "^4.0.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
84% confidence
Finding

@types/node-fetch uses a non-exact version range, allowing dependency drift across installations. As a dev dependency its runtime impact is limited, but it still creates avoidable supply-chain and reproducibility risk during development and CI.

Content

Scanner excerpt · package.json (reported line 25)May include surrounding context.

json
},
  "devDependencies": {
    "@types/node": "^24.3.0",
    "@types/node-fetch": "^2.6.13",
    "typescript": "^5.9.2",
    "vitest": "^4.0.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
85% confidence
Finding

typescript is not pinned to an exact version, which can cause differing compiler behavior and pull in upstream changes without deliberate approval. This is mainly a build-chain integrity concern rather than a direct runtime exploit in this skill.

Content

Scanner excerpt · package.json (reported line 26)May include surrounding context.

json
"devDependencies": {
    "@types/node": "^24.3.0",
    "@types/node-fetch": "^2.6.13",
    "typescript": "^5.9.2",
    "vitest": "^4.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

vitest is declared with a caret range, making installs non-deterministic and increasing exposure to unsafe upstream releases. In this file that risk is amplified because the selected version line is also associated with known critical advisories.

Content

Scanner excerpt · package.json (reported line 27)May include surrounding context.

json
"@types/node": "^24.3.0",
    "@types/node-fetch": "^2.6.13",
    "typescript": "^5.9.2",
    "vitest": "^4.0.0"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The formatter hard-codes toLocaleString('en-US', ...), which imposes a specific locale on all rendered numeric output. The file does not offer a user locale choice or document why US formatting is required, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.