Back to skill

Security audit

Voyage AI CLI

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Voyage AI and MongoDB Atlas helper, but it uses an unpinned global CLI install and gives commands that can send text externally or change Atlas data and indexes without enough guardrails.

Install only if you trust the voyageai-cli package and publisher, prefer a pinned version, avoid sudo or administrator installs, use least-privilege Atlas credentials, and treat store, ingest, index create, and index delete commands as operations that can affect real databases. Do not send private text to the embedding or reranking service unless that external transfer is acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:26
Finding

Unpinned Third-Party npm Package Installed Globally

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-30 and 39-41
Vulnerability Type: Unpinned global dependency installation
Risk Level: Medium

Vulnerable Code

yaml
install:
  - id: npm
    kind: npm
    package: voyageai-cli
    global: true
bash
npm install -g voyageai-cli

Technical Analysis

The Skill instructs users to install voyageai-cli from the npm registry without specifying an exact, reviewed version or an integrity constraint. Consequently, npm resolves the package to whichever version is current at installation time. The effective code executed by the Skill can therefore change after this repository has been audited.

npm packages may execute package-controlled lifecycle scripts during installation. Because the package is installed globally, those scripts run with the permissions of the user invoking npm and can modify globally accessible command locations. This creates a supply-chain exposure if the package publisher account, npm package, release pipeline, or a future package version is compromised.

This finding does not establish that the current voyageai-cli package is malicious. The vulnerability is the unsafe dependency acquisition and installation practice, which places mutable third-party code outside the reviewed project into a trusted execution path.

Attack Path

  1. An attacker compromises the npm publisher account, release process, or another component used to publish voyageai-cli.
  2. The attacker publishes a malicious version under the legitimate package name.
  3. A user follows the Skill instructions and executes npm install -g voyageai-cli without a version constraint.
  4. npm resolves and downloads the attacker-controlled release.
  5. Any malicious npm lifecycle script executes during installation with the invoking user's permissions.
  6. The installed vai executable can subsequently execute attacker logic when the user invokes ...[truncated 975 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact version that has been reviewed, for example:

    yaml
    package: voyageai-cli@1.4.0
    

    and:

    bash
    npm install -g voyageai-cli@1.4.0
    
  2. Prefer a project-local dependency over a global installation so the package is isolated from global command paths:

    bash
    npm install --save-exact voyageai-cli@1.4.0
    npx vai --help
    
  3. Commit and enforce a lockfile with npm integrity hashes where the packaging format supports it. Use npm ci rather than unconstrained installation in automated environments.

  4. Verify package provenance, publisher identity, repository ownership, signatures or attestations, and the integrity of the selected release before recommending it.

  5. Disable lifecycle scripts during installation when they are not required:

    bash
    npm install --save-exact --ignore-scripts voyageai-cli@1.4.0
    

    If lifecycle scripts are required, review them before installation.

  6. Perform installation as an unprivileged user. Do not use sudo or an administrator account.

  7. Run the CLI in a restricted environment with only the minimum required credentials, filesystem access, and network permissions. MongoDB credentials should follow least privilege and should not grant unrelated administrative capabilities.

  8. Establish a controlled update process in which newer dependency versions are reviewed and tested before the pinned version is changed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list contains broad phrases such as 'similarity search', 'store embeddings', and 'explain embeddings' that can match many ordinary user requests, causing this skill to be invoked outside clearly scoped Voyage AI or Atlas tasks. Because the skill can send content to an external API and perform MongoDB operations, over-broad routing increases the chance of unintended data disclosure or unintended modifications when the wrong skill is selected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill presents commands that transmit user-provided text to Voyage AI and can store data, create indexes, and delete indexes in MongoDB Atlas, but it does not warn about external data transfer or destructive database actions. In an agent setting, this omission can lead users or orchestrators to invoke the skill without informed consent, risking sensitive data exposure and unintended changes to production databases.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.