Back to skill

Security audit

Wei Cross Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for multi-model research, but users should review it because it recommends an unsafe installer pattern and automatically stores prompts and model outputs locally.

Before installing, avoid the curl | bash Bun installer and use a package manager or verified download instead. Do not send secrets, personal data, confidential business data, or unreleased financial information unless each configured model provider is approved for it, and remember that the skill saves prompts and raw outputs locally until you delete them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:79
Finding

Unpinned Remote Installer Is Piped Directly to a Shell

Content
View full analysis
= 1.0 ### Install Bun ```bash curl -fsSL https://bun.sh/install | bash ``` ``` ### Technical Analysis The installation instructions download a mutable script from an external URL and immediately execute it with Bash. The downloaded content is not displayed for review, pinned to a version, checked against a cryptographic digest, or verified using a signature. Although `bun.sh` is the documented Bun project domain, this pattern transfers control of the effective installation payload to external infrastructure after the Skill has been reviewed. Compromise of the upstream server, its deployment process, DNS resolution, or a trusted delivery component could cause arbitrary replacement code to be executed. Installing Bun is necessary for the declared functionality, but executing an unverified network response directly is not the minimum privilege or minimum-risk method required to install it. ### Attack Path 1. An attacker compromises or gains the ability to modify the script returned by `https://bun.sh/install`. 2. A user follows the Skill documentation and runs the provided command. 3. `curl` downloads the attacker-controlled response. 4. The shell pipeline passes that response directly to Bash without verification or inspection. 5. Bash executes the payload with all permissions available to the user who launched the command. 6. The payload can access or modify any files, credentials, processes, or configuration available to that user. ### Impact Assessment Successful exploitation provides arbitrary command execution under the installing user's account. If the user runs the command with elevated privileges or from a privileged environment, the payload inherits that broader scope. Potential consequences include cre ...[truncated 303 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/agent.ts:526
Finding

Untrusted Model Responses Can Inject Instructions into Judge Synthesis

Content
View full analysis
` Model: ${r.model} Summary: ${r.summary} Key Points: ${r.keyPoints.join(', ')} Confidence: ${r.confidence} `).join('\n---\n'); const template = domain === 'financial' ? JUDGE_FINANCIAL_PROMPT_TEMPLATE : JUDGE_PROMPT_TEMPLATE; const judgePrompt = template .replace('{{query}}', query) .replace('{{modelResponsesText}}', modelResponsesText) .replace('{{critiqueSection}}', ''); const messages: ChatMessage[] = [ { role: 'user', content: judgePrompt }, ]; const response = await this.callModel( this.judgeModel, messages, { maxTokens: appConfig.max_tokens_judge } ); ``` The corresponding judge template places the interpolated content directly in an instruction-bearing prompt: ```text Question: {{query}} Model Responses: {{modelResponsesText}}{{critiqueSection}} ``` ### Technical Analysis Responses returned by external answering models are untrusted content. The implementation parses those responses and directly interpolates their summaries and key points into the same user message that contains instructions for the judge. There is no robust instruction/data separation. A response containing text such as a request to disregard the synthesis format can therefore be interpreted by the judge as an instruction rather than as evidence to evaluate. The original query is passed through a blacklist-based `sanitizeInput()` function, but that function does not process model responses before judge synthesis. In addition, phrase blacklists cannot comprehensively prevent prompt injection because equivalent instructions can be expressed through paraphrasing, encoding, multilingual text, or fragmented tokens. ### Attack Path 1. An attacker supplies a crafted research query intended to in ...[truncated 1255 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/agent.ts:590
Finding

Queries and Raw Model Responses Are Persisted in Plaintext

Content
View full analysis
{ if (response) { const filename = `${response.model}-${timestamp}.txt`; const filepath = join(dir, filename); const content = [ `Model: ${response.model}`, `Timestamp: ${timestamp}`, `Query: [saved in report]`, ``, `=== Summary ===`, response.summary, ``, `=== Key Points ===`, ...response.keyPoints.map(p => `- ${p}`), ``, `=== Confidence ===`, `${response.confidence}`, ``, `=== Raw Response ===`, response.rawResponse || '', ].join('\n'); writeFileSync(filepath, content, 'utf-8'); console.log(`[ResearchAgent] Saved: intermediate/${filename}`); } }); ``` The report also retains the complete query and judge output: ```ts const filepath = join(dir, `report-${timestamp}.txt`); const content = [ `Query: ${query}`, `Timestamp: ${timestamp}`, `Models: ${responses.map(r => r.model).join(', ')}`, ``, judgeRaw, ].join('\n'); writeFileSync(filepath, content, 'utf-8'); ``` ### Technical Analysis Every successful run stores model responses in `intermediate/` and stores the query and final judge output in `reports/`. The implementation does not provide a no-retention mode, automatic deletion, content redaction, encryption, or an explicit restrictive file mode. The documentation warns users not to submit secrets, personally identifiable information, or confidential data. That warning reduces expected exposure but does not protect against accidental submission or sensitive content generated by a model. The files are created using default process and operating-system permissions. Their effective accessibility therefore depends on the runtime environment and its `umask`, rather than on an explicit ap ...[truncated 1092 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (58)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 2)May include surrounding context.

text
# Environment variables
.env
.env.local
.env.*.local

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 3)May include surrounding context.

text
# Environment variables
.env
.env.local
.env.*.local

# Node.js

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The top-level description emphasizes answer cross-validation, but the body also documents filesystem writes, routing/classification behavior, and other operational side effects that are not reflected in the concise declared purpose. Security reviewers and users may therefore underestimate data retention and execution behavior, leading to accidental disclosure of sensitive prompts or outputs to disk or external providers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level description emphasizes answer cross-validation, but the body also documents filesystem writes, routing/classification behavior, and other operational side effects that are not reflected in the concise declared purpose. Security reviewers and users may therefore underestimate data retention and execution behavior, leading to accidental disclosure of sensitive prompts or outputs to disk or external providers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The top-level description emphasizes answer cross-validation, but the body also documents filesystem writes, routing/classification behavior, and other operational side effects that are not reflected in the concise declared purpose. Security reviewers and users may therefore underestimate data retention and execution behavior, leading to accidental disclosure of sensitive prompts or outputs to disk or external providers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The top-level description emphasizes answer cross-validation, but the body also documents filesystem writes, routing/classification behavior, and other operational side effects that are not reflected in the concise declared purpose. Security reviewers and users may therefore underestimate data retention and execution behavior, leading to accidental disclosure of sensitive prompts or outputs to disk or external providers.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The installation instructions recommend fetching a remote script and piping it directly to a shell. This bypasses integrity verification and gives immediate code-execution privileges to whatever content is served at that URL or delivered through a supply-chain or TLS interception event.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

Install Bun

bash
curl -fsSL https://bun.sh/install | bash

Or on macOS with Homebrew:

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The explicit use of a shell pipeline into bash is a classic chaining-abuse pattern because it combines remote content retrieval with immediate execution in one step. In this skill context, users following setup instructions could unknowingly execute malicious or tampered installer code on their host system.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

Install Bun

bash
curl -fsSL https://bun.sh/install | bash

Or on macOS with Homebrew:

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins axios 1.13.6, and the reported advisories include network-relevant issues such as SSRF-related NO_PROXY bypasses and prototype-pollution-assisted request/response compromise. In a skill explicitly designed to query multiple LLMs and external services in parallel, an HTTP client weakness is directly in the trust boundary and increases exposure because outbound requests, proxy handling, and remote response processing are core behavior.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
82% confidence
Finding

form-data 4.0.5 has a reported CRLF injection issue via unescaped multipart field names and filenames. While exploitability depends on whether the skill constructs multipart requests from untrusted input, this project's purpose involves external querying and aggregation, so if any uploads or multipart submissions are supported later, the dependency could enable request smuggling or header injection behaviors.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

The manifest permits installation of an axios version identified by the scanner as vulnerable, including advisories affecting SSRF and man-in-the-middle/prototype-pollution-related abuse. In a skill explicitly designed to query multiple external LLMs and remote endpoints, an HTTP client flaw is more dangerous because it sits directly on the network boundary and may expose tokens, requests, responses, or allow policy bypasses when making outbound calls.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/agent.ts (reported line 5)May include surrounding context.

ts
/**
 * Cross Research Agent
 *
 * Core implementation of the cross-research skill.
 * Queries multiple LLMs in parallel and synthesizes their responses into a single high-quality answer.
 */

import { readFileSync, mkdirSync, writeFileSync } from 'fs';
import { dirname, join } from 'path';
import { fileURLToPath } from 'url';
import { BailianClient, OpenRouterClient, OpenAICompliantClient } from './clients/index.js';
import type { ChatMessage, ChatCompletionResponse } from './clients/bailian.js';

/** Configuration file structure */
interface ConfigFile {
  judge_model: string;
  max_models: number;
  max_tokens: number;
  max_tokens_judge: number;
  depth: string;
  models: Rec

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · scripts/agent.ts (reported line 265)May include surrounding context.

ts
/**
   * Input sanitization - protect against prompt injection
   *
   * SECURITY NOTE: The patterns below (e.g., "ignore previous instructions") are
   * used for DEFENSIVE purposes to detect and neutralize potential prompt injection
   * attacks. These strings are matched against user input and redacted to prevent
   * manipulation of the LLM. This is a security feature, not a vulnerability.

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · scripts/agent.ts (reported line 286)May include surrounding context.

ts
/**
   * Input sanitization - protect against prompt injection
   *
   * SECURITY NOTE: The patterns below (e.g., "ignore previous instructions") are
   * used for DEFENSIVE purposes to detect and neutralize potential prompt injection
   * attacks. These strings are matched against user input and redacted to prevent
   * manipulation of the LLM. This is a security feature, not a vulnerability.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/clients/bailian.ts (reported line 7)May include surrounding context.

ts
* A reusable HTTP client for making requests to the OpenRouter API.
 * Supports rate limiting, retries, and configurable timeouts.
 *
 * Environment variables are automatically loaded from .env file by Bun.
 * See: https://bun.sh/docs/runtime/env
 */

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/clients/openai_compliant.ts (reported line 10)May include surrounding context.

ts
* A reusable HTTP client for making requests to the OpenRouter API.
 * Supports rate limiting, retries, and configurable timeouts.
 *
 * Environment variables are automatically loaded from .env file by Bun.
 * See: https://bun.sh/docs/runtime/env
 */

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/clients/openrouter.ts (reported line 7)May include surrounding context.

ts
* A reusable HTTP client for making requests to the OpenRouter API.
 * Supports rate limiting, retries, and configurable timeouts.
 *
 * Environment variables are automatically loaded from .env file by Bun.
 * See: https://bun.sh/docs/runtime/env
 */

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/index.ts (reported line 446)May include surrounding context.

ts
Examples:
  bun run scripts/index.ts "What are the economic impacts of AI?"
  bun run scripts/index.ts -m glm-5,gpt-5.4 "Explain quantum computing"
  bun run scripts/index.ts -t financial "Will the Fed cut rates in 2026?"
  bun run scripts/index.ts -t technical "How do I implement a distributed transaction?"
  bun run scripts/index.ts --json "Latest AI breakthroughs"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares required environment variables and clearly performs external network calls to third-party model APIs, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization and review gap: operators may not realize the skill can exfiltrate user prompts or sensitive content to external services, especially since the skill itself warns that queries are sent upstream.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation presents structured JSON responses while also stating that execution writes text reports and raw intermediate model outputs to disk. That inconsistency matters because users may assume ephemeral API-style handling, while the skill may persist potentially sensitive prompts, model outputs, and judge analyses in local files without strong visibility.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger use cross-research is short and generic enough that it could overlap with ordinary conversational phrasing about research workflows. The document does not provide an explicit bounded trigger list, exclusion conditions, or negative examples to clarify when the skill should or should not activate from similar phrasing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest/config file sets the region to "cn", which imposes a locale/region choice at the configuration level. Under the policy, forcing a specific language or locale without user opt-in or clear justification is a natural-language policy concern, and no such opt-in or justification is present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON manifest sets the region to "cn", which imposes a locale/region constraint in configuration. Under the policy, forcing a specific locale is a violation unless the skill offers user choice or the regional restriction is clearly documented and justified; neither is present in this file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt requires model summaries to be written "in Chinese" on L14-L15, but L30 instructs the model to "Respond in user's language." These instructions are in direct conflict when the user's language is not Chinese, creating intent ambiguity in the skill's judging behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt explicitly requires model summaries to be written 'in Chinese' on L14-L15, while L30 says to 'Respond in user's language.' This creates a natural-language policy violation because it imposes a specific language without user opt-in and may override the user's locale preference for part of the output.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/clients/bailian.ts:140

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/clients/openai_compliant.ts:152

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/clients/openrouter.ts:120

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/clients/openai_compliant.ts:214

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/index.ts:218