Back to skill

Security audit

Shadows Bug Hunter

Security checks for vulnerabilities and agentic risk

Overview

The skill is a reasonable debugging guide, but it needs review because some suggested JavaScript test commands can download and run unverified tools despite claiming no network access.

Review before installing. Use this skill only in trusted repositories or sandboxes, and prefer local-only test runner commands such as npm exec --no-install or direct node_modules binaries so the agent does not automatically download and run tools from a package registry.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Unpinned On-Demand Package Execution Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs use of npx jest --version to detect a test runner. npx may download and execute a package when it is not already installed locally, which means merely following the detection step can trigger unpinned code execution from a registry. In a debugging skill intended for arbitrary repositories, that creates unnecessary supply-chain and arbitrary execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill recommends npx vitest --version for auto-detection. As with other npx invocations, this can fetch and run an unpinned package if absent, exposing the agent to registry poisoning, typo-squatting, or unexpected package lifecycle script execution. Because this occurs during a preliminary detection step, the risk is broader than a deliberate trusted build action.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The same Technique 4 step also includes npx vitest run {test_file}. This presents unpinned package execution risk via npx, and because the skill is expressly for debugging potentially untrusted codebases, the operational context makes executing fetched tooling more dangerous than in a tightly controlled CI environment. An attacker could exploit the package resolution path or rely on absent local installs to trigger external code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The same Technique 4 step also includes npx vitest run {test_file}. This presents unpinned package execution risk via npx, and because the skill is expressly for debugging potentially untrusted codebases, the operational context makes executing fetched tooling more dangerous than in a tightly controlled CI environment. An attacker could exploit the package resolution path or rely on absent local installs to trigger external code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The full-suite verification step includes npx vitest run, again creating a path for unpinned package download and execution. In the context of an agent skill, this is a true security issue because the skill operationalizes a command that may execute external code not controlled by the repository owner or the user. The existing note about trusted repositories addresses repo code execution but not package-manager mediated tool retrieval.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The full-suite verification step includes npx vitest run, again creating a path for unpinned package download and execution. In the context of an agent skill, this is a true security issue because the skill operationalizes a command that may execute external code not controlled by the repository owner or the user. The existing note about trusted repositories addresses repo code execution but not package-manager mediated tool retrieval.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.