Back to skill

Security audit

THE_TIME_MASHEEN

Security checks for vulnerabilities and agentic risk

Overview

The skill has a clear web-scraping purpose, but its install and optional plugin instructions expand trust and execution risk enough that users should review it carefully before installing.

Install only if you are comfortable reviewing shell installers and third-party dependencies. Prefer downloading and inspecting the installer first, pinning versions where possible, avoiding elevated privileges, using a virtual environment instead of global installs, and using authenticated or stealth scraping only on sites where you have clear authorization. Treat the CLI-Anything plugin instructions as separate and optional, not required for this skill.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:5
Finding

Mutable Remote Installation Script Is Downloaded and Immediately Executed

Content
View full analysis
Remediation
View remediation
/install.sh ``` 3. Pin the URL to a full immutable Git commit rather than `main`. 4. Publish and require verification of a SHA-256 checksum or cryptographic signature: ```bash echo " install.sh" | sha256sum --check - ``` 5. Instruct users to inspect the downloaded script before running it: ```bash less install.sh bash install.sh ``` 6. Prefer distributing a signed release artifact through a controlled release process. 7. Ensure documentation clearly states that the installer should not be run with elevated privileges unless each privileged action is separately justified. ]]>

T08 · Insecure Dependencies

Warning
Location
install.sh:27
Finding

Unpinned Dependencies Are Installed with Lifecycle Code Execution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:176
Finding

Unrelated Third-Party Agent Plugin Installation Expands the Trust Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

Find all snapshots of a URL

bash
curl -s "https://web.archive.org/cdx/search/cdx?url=example.com&output=json&fl=timestamp,statuscode&filter=statuscode:200&limit=20"

One snapshot per year (change tracking)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/wayback.md (reported line 24)May include surrounding context.

bash
# All 200-OK snapshots of a URL
curl -s "https://web.archive.org/cdx/search/cdx?url=example.com&output=json&filter=statuscode:200&fl=timestamp,original"

# One snapshot per year (change tracking)
curl -s "https://web.archive.org/cdx/search/cdx?url=example.com&output=json&collapse=timestamp:4&fl=timestamp,statuscode&filter=statuscode:200"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/wayback.md (reported line 54)May include surrounding context.

scrapling extract get "https://web.archive.org/web/20230601000000/https://example.com/" archive.md

Most recent snapshot

curl -s "https://archive.org/wayback/available?url=example.com" | python3 -c "import sys,json; d=json.load(sys.stdin); print(d['archived_snapshots']['closest']['url'])"

text

## `ia` CLI — Internet Archive Items

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README instructs users to execute a remote script directly with bash <(curl ...), which bypasses normal review of downloaded code and gives the fetched content immediate shell execution privileges. If the upstream repository, network path, or referenced script is compromised, users can suffer arbitrary code execution on their machine.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is extremely broad and overlaps with many ordinary web/data requests, making it likely this skill will auto-activate in contexts the user did not intend. Because the skill includes browser automation, login flows, and protected-site scraping, ambiguous invocation boundaries raise the chance of unnecessary navigation, credential handling, or data collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description explicitly promotes logging into sites and extracting from login-gated or paywalled pages, but the initial invocation text does not foreground credential safety, sensitive session handling, or authorization checks. In practice, this can normalize entering passwords into agent-driven flows and scraping account-restricted content without sufficient safeguards, creating risk of credential exposure, privacy violations, and policy abuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill unexpectedly appends instructions for installing and using a separate plugin that can build a CLI harness for arbitrary software, which materially expands capability beyond the stated scraping/Wayback/browser-automation scope. This kind of hidden scope expansion is dangerous because it can route the agent into installing new tooling and interacting with unrelated local applications, increasing attack surface and enabling privilege creep.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reference explicitly documents stealth scraping, anti-bot evasion, and Cloudflare challenge solving without any warning about legal, policy, privacy, or operational implications. In an agent skill context, this normalizes potentially abusive automation and could lead users to deploy techniques that violate terms of service, evade defenses, or trigger harm to third-party systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The Docker example pulls and runs an unpinned image tag, which makes the referenced artifact mutable over time. Users may unknowingly execute a different image than the author originally tested, increasing supply-chain risk if the latest tag is replaced, compromised, or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Running a container from an unpinned image reference inherits the same supply-chain risk as pulling it: the image contents can change without notice. Because this is an execution example, it directly encourages users to run potentially unreviewed code if the upstream image is altered or maliciously replaced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file includes commands that save output to files such as output.md and old.md, but it does not warn users that running them will create or overwrite local files with scraped content. For a usage guide, a brief disclosure about local file writes would satisfy the warning requirement for data-affecting behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.