Back to skill

Security audit

AgentGuard Burn

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it directs users to run mutable npm code that reads local Claude Code and Codex transcripts and can optionally install persistent agent-control hooks.

Review this carefully before installing or running. The skill's purpose is legitimate and disclosed, but use it only if you trust the npm package and plugin source, and avoid running it in workspaces where local agent transcripts may contain secrets unless you have validated the package version or use a pinned/trusted install path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (12)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The manifest-level description references npx agentguard-burn why without a version pin, signaling that the skill's intended execution model is live retrieval and execution from npm. As a skill artifact, this is more dangerous than a generic doc snippet because assistants may surface and encourage the exact command automatically, amplifying supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs use of npx agentguard-burn why without pinning an exact package version or integrity, which causes code to be fetched and executed from npm at runtime. If the package is compromised, republished maliciously, or resolved to an unexpected version, arbitrary code could run on the user's machine while this tool also has access to local Claude Code/Codex transcripts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The primary usage instruction tells the operator to run npx agentguard-burn why, which performs remote package resolution and code execution without version pinning. In this context the tool reads local transcripts, so a compromised package could exfiltrate sensitive session history or execute arbitrary local actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This line again directs users to execute an unpinned npm package, allowing whatever version npm resolves at that moment to run locally. Because the skill specifically targets local transcript analysis, the blast radius includes potentially sensitive developer conversations, prompts, paths, and tool outputs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Suggesting ! npx agentguard-burn why inside Claude Code still results in unpinned remote code execution from npm. Embedding the command in an assistant skill increases the chance users will run it with little scrutiny, which makes supply-chain compromise more dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This duplicate finding corresponds to the second unpinned command on the same line (enforce). It carries the same supply-chain risk: executing mutable npm content locally without version control.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The calendar command is another unpinned runtime fetch-and-execute path from npm. Even though its functional purpose is reporting token history, the security issue is the same arbitrary code execution risk from a mutable external package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The compare command repeats the same unsafe pattern of unpinned npx execution. Any compromise of the package or dependency chain could run attacker-controlled code on the local machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The rewrites command is another instance of unversioned remote package execution. The skill context makes this more sensitive because the tool operates over local developer transcripts and metadata that may contain secrets or proprietary information.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The quiet on/off examples continue the same pattern of executing an unpinned npm package via npx. Repetition throughout the skill normalizes the unsafe practice and increases the likelihood of users executing mutable code from the registry.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.