Back to skill

Security audit

Prethereum

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent verifier/notary integration that discloses its network behavior and does not show hidden collection, persistence, or destructive behavior.

Before installing, pin the `prethereum` package version where possible, inspect the package as suggested, and only commit data you are comfortable sending to the configured notary endpoint. Do not send credentials, private keys, or sensitive personal data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:51
Finding

Unpinned npm Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 51
Vulnerability Type: Supply-chain risk caused by an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

bash
npm install prethereum

Technical Analysis

The installation command does not specify an exact package version or cryptographic integrity value. Consequently, npm resolves whichever version is currently selected by the registry and applicable package metadata at installation time.

The installed artifact may therefore differ from the version reviewed during this audit. If the package publisher account, npm registry entry, or a future package release is compromised, users following this instruction could install attacker-controlled code. npm packages may execute lifecycle scripts during installation, so exploitation may occur without the user explicitly invoking the installed library.

The document pins @prethereum/mcp@0.1.0 elsewhere, but that does not mitigate this separate unpinned installation of the prethereum package or risks from unpinned transitive dependencies.

Attack Path

  1. An attacker compromises the prethereum npm package, its publisher account, or a future release process.
  2. The attacker publishes a malicious version or introduces a malicious transitive dependency.
  3. A user follows the documented npm install prethereum instruction.
  4. npm resolves and downloads the attacker-controlled release because no exact version or integrity constraint is specified.
  5. Malicious package lifecycle scripts may execute during installation, or malicious logic may execute when the package is imported.
  6. The payload runs with the privileges of the user or automation account performing the installation.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's privileges. Depending on that account's permissions and environment, the attacker could ac ...[truncated 243 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the unversioned command with an exact, reviewed package version, for example:

    bash
    npm install prethereum@<audited-exact-version> --save-exact
    
  • Commit and enforce a lockfile containing registry-resolved integrity hashes.

  • Use npm ci for reproducible automated installations instead of allowing dependency re-resolution.

  • Review the package archive before installation with npm pack, as already recommended for the MCP package.

  • Disable lifecycle scripts with --ignore-scripts when they are not required. If scripts are necessary, inspect them before execution.

  • Pin and audit transitive dependencies, monitor package ownership and release changes, and use automated dependency and provenance verification.

  • Perform installation in a least-privileged, isolated environment without unnecessary credentials or sensitive environment variables.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

HTTP API

bash
curl -X POST http://localhost:3030/commit \
  -H "Content-Type: application/octet-stream" \
  --data-binary @output.json

Static analysis

No suspicious patterns detected.