Back to skill

Security audit

Contextui

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a coherent ContextUI workflow toolkit, but it includes high-impact marketplace, local execution, and persisted MCP capabilities with several under-scoped safety gaps users should review before installing.

Install only if you are comfortable giving ContextUI broad local workflow-development authority. Avoid providing CONTEXTUI_API_KEY unless you need Exchange features, review workflows before publishing or downloading them, require explicit confirmation before comments/likes/deletes/billing actions, pin and review pip/npm dependencies, and do not connect persistent external MCP servers unless you trust the exact command or URL. Treat downloaded marketplace workflows as untrusted code and stage/validate them before placing them in an executable workflow directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
references/server-launcher.md:68
Finding

Python Backend Exposed on All Network Interfaces with Permissive CORS

Content
View full analysis
1 else 8800 uvicorn.run(app, host="0.0.0.0", port=port) ``` ### Technical Analysis The recommended backend pattern binds Uvicorn to `0.0.0.0`, causing the service to listen on every available network interface rather than only the loopback interface. This contradicts the localhost-only security model declared in `SKILL.md` and `SECURITY.md`. The example also enables wildcard origins, methods, and headers through CORS. Consequently, any origin accepted by the browser's network security model can interact with these endpoints. Independent of CORS, another device on the same reachable network can directly send requests to the exposed port. The template does not add authentication or authorization. Workflows that copy this canonical example and later introduce file processing, model management, command execution, or sensitive-data endpoints may expose those operations without access control. ### Attack Path 1. A user follows the documented ServerLauncher backend example. 2. The workflow starts Uvicorn on `0.0.0.0:8800`, or another configured port. 3. The operating system firewall permits access from a local or otherwise connected network. 4. An attacker discovers the service through port scanning, service enumeration, or knowledge of the documented default ports. 5. The attacker calls unauthenticated workflow endpoints directly. 6. If those endpoints process local files, manage models, or pe ...[truncated 1010 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/exchange.md:132
Finding

Marketplace Download Example Allows Path Traversal and Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/mcp-tools.md:370
Finding

Unpinned MCP Package Is Downloaded and Executed Through npx

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:423
Finding

ServerLauncher Installs Mutable PyPI Dependencies Without Version or Hash Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented primarily as a local-first workflow/UI toolkit, but the documentation also enables remote Exchange operations including search, download, commenting, likes, and publishing via external APIs and S3 uploads. That mismatch can mislead users or policy systems into treating the skill as purely local when it can transmit data and perform account-linked marketplace actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata claims local-only operation and no remote execution, but this reference explicitly supports connecting to external MCP servers via arbitrary stdio commands or HTTP URLs. That materially expands the trust boundary, since external MCP servers can introduce unreviewed tools, data flows, and code paths inconsistent with the stated security model.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SECURITY.md (reported line 14)May include surrounding context.

md
This skill grants an agent broad local development capabilities. Here's exactly what it can and cannot do:

### What the agent CAN do
- **Read/write workflow files** — React TSX source files within the ContextUI workflows directory, using absolute paths
- **Start Python servers** — from existing local scripts via `python_start_server`. Servers bind to `127.0.0.1` (localhost)
- **Create virtual environments and install pip packages** — the ServerLauncher pattern creates venvs and installs packages from PyPI. This involves network downloads
- **Read local directories** — including `~/.cache/huggingface` for model cache monitoring in ML workflows (documented in `references/cache-monitoring.md`)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents shell-based usage (mcporter, scripts/exchange.sh, environment variable export) and operational capabilities, but it does not declare an explicit tool/permission scope. In an agent setting, that omission weakens policy enforcement and can let the skill invoke broader local command execution than a reviewer or runtime expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The publishing flow describes direct uploads to S3 but does not prominently warn that local workflow contents leave the machine and are sent to third-party infrastructure. In a skill advertised as local-first, that omission increases the risk of accidental disclosure of proprietary code, embedded secrets, or sensitive data packaged with a workflow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/exchange-api.md (reported line 55)May include surrounding context.

bash
# Search workflows
curl -H "Authorization: Bearer $CONTEXTUI_API_KEY" \
  "https://contextui.ai/.netlify/functions/marketplace?search=video"

# Filter by category

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents a destructive operation that permanently removes listings and associated S3 files, but it does not provide a prominent safety warning beyond the inline parenthetical note. Under the missing-warning criteria for markdown files, behaviours affecting user data or system integrity should be clearly warned about before use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation exposes an admin delete endpoint without clearly marking it as destructive or advising confirmation safeguards. In an agent-facing skill, examples and endpoint lists can be used directly for automation, so missing cautions can lead to accidental or unauthorized deletion attempts against listings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The billing and subscription endpoints are documented without warnings that they may create charges, change account balances, or alter subscription state. In an agent integration context, this is dangerous because autonomous or mistaken calls could trigger financial actions without clear consent boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/exchange.md (reported line 55)May include surrounding context.

bash
# List all workflows (paginated)
curl -H "Authorization: Bearer ctxk_..." \
  "https://contextui.ai/.netlify/functions/marketplace?limit=20"

# Search by keyword

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example shows programmatically downloading files from signed remote URLs and writing them directly into the local workflows directory, which can normalize unsafe import behavior for untrusted workflow code. In this skill's context, downloaded workflows may later be opened or executed by ContextUI, so omitting warnings about trust, validation, and user confirmation increases the risk of importing malicious content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

python_test_endpoint accepts an arbitrary full URL and the examples and parameter description do not constrain it to 127.0.0.1 or workflow-owned backends. This can enable agent-directed requests to internal network services or external endpoints, expanding the tool from local backend testing into general HTTP request capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The UI inspection features include screenshots, DOM extraction, style capture, and optional hidden-element enumeration, all of which can expose sensitive information present in the app window. Without prominent warnings and scoping safeguards, an agent can collect secrets, personal data, or hidden state not intended for routine automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The click, drag, and typing tools can submit forms, trigger destructive actions, alter configuration, or interact with the wrong control if selectors/text matching are ambiguous. Documenting these capabilities without warnings or safety patterns increases the risk of unintended state changes and potentially harmful automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

open_html_app launches content in the system default app, which escapes the documented ContextUI window scope and moves execution or rendering into a less controlled environment. This increases the chance of unintended browser execution, broader filesystem/application interaction, and user confusion about what is being automated or trusted.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The example command uses npx -y @modelcontextprotocol/server-filesystem without pinning an exact version, so execution may pull whatever package version is current at install time. Because npx executes fetched code locally, this creates a supply-chain risk where a compromised upstream package or breaking update could lead to unexpected code execution on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation promotes a flow that performs package installation and optional auto-start automatically, but does not clearly warn that this changes the local system environment and executes newly installed code. In a local-first desktop agent platform, silent or underexplained install-and-run behavior increases the risk of users launching unreviewed dependencies without informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation example starts Uvicorn with host='0.0.0.0', which exposes the backend on all network interfaces instead of localhost-only. In this skill's context, that contradicts the stated trust model that Python backends bind to localhost, and could unintentionally expose unauthenticated development endpoints to the local network.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · references/workflow-guide.md (reported line 286)May include surrounding context.

md
const [loading, setLoading] = React.useState(true);

React.useEffect(() => {
  fetch('http://127.0.0.1:8800/data')
    .then(res => res.json())
    .then(d => { setData(d); setLoading(false); })
    .catch(() => setLoading(false));

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/exchange.sh (reported line 32)May include surrounding context.

sh
;;
  get)
    [ -z "$2" ] && echo "Usage: exchange.sh get <uuid>" && exit 1
    curl -s -H "Authorization: Bearer $KEY" "$BASE/marketplace?id=$2"
    ;;
  category)
    [ -z "$2" ] && echo "Usage: exchange.sh category <category>" && exit 1

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script exposes a destructive hard-delete operation with no interactive confirmation, dry-run, or additional safeguard. In a CLI used with authenticated credentials, a mistyped command, copied snippet, or accidental automation call could irreversibly delete a listing, causing permanent data loss for the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The examples for browsing, downloading, liking, and commenting on the Exchange omit a clear disclosure that these actions contact remote services and may be tied to the user's API key or account identity. While not inherently unsafe, the missing notice can cause unintended external communication and activity attribution.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
66% confidence
Finding

The example workflow source location includes an explicit absolute path under a user's home directory (/Users/jasonclissold/...). While presented as documentation, it discloses personally identifying local filesystem context in natural language rather than via code or explicit leak terminology. This creates a minor data-exposure risk because agents or downstream consumers may surface or reuse that path unnecessarily.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/server-launcher.md (reported line 3)May include surrounding context.

md
# ServerLauncher — Python Backend Pattern (v3.0.0)

The standard pattern for any ContextUI workflow with a Python backend. Two files handle everything: Python detection → venv selection → GPU detection → package installation (GPU-aware) → server start/stop → connection polling. Cross-platform (Windows, macOS, Linux).

## Overview

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file states that the hook remembers port, venv, and auto-start preferences in localStorage, which is user-environment data persistence. For markdown files, behaviors that affect user data or privacy should be disclosed clearly, but no warning or retention note is provided here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.