T08 · Insecure Dependencies
- Location
SKILL.md:361- Finding
Unpinned npm Package Is Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is openly designed to build persona packs, but it handles sensitive private communications and local skill files with several under-scoped safety controls.
Review before installing. Use this only with data you are authorized to process, avoid building personas from private third-party communications without consent, run it in a restricted working directory, and pin or preinstall the OpenPersona tool instead of using live `npx` commands. Do not use rollback, update, or init commands with untrusted slug/version values until path validation is added.
SKILL.md:361Unpinned npm Package Is Downloaded and Executed
scripts/skill_writer.py:40Unsanitized Persona Slug Permits Path Traversal Outside the Skills Directory
scripts/version_manager.py:57Rollback Path Traversal Can Recursively Delete and Replace Unintended Directories
The declared description presents an end-to-end persona distillation and packaging skill. This code chunk does not perform persona analysis, cloning, profile extraction, or OpenPersona pack creation. Instead, it is a support script for preprocessing input data: detecting SQLite databases, extracting message text from known schemas, parsing generic JSON/text exports, filtering by target sender, and reducing large files via sampling. These behaviors may support the broader skill, but the code itself materially differs from the declared primary purpose and omits the headline capabilities described.
The declared description promises a full persona-distillation pipeline: ingesting various content sources, extracting a persona representation, and producing an OpenPersona skill pack. The supplied code does none of that. It only supports three CLI actions: listing existing skills by reading meta.json files, initializing a directory with a template meta.json, and updating metadata via a provided JSON patch. While this may be a small supporting component of a larger system, this chunk's actual behavior is materially narrower and different from the declared end-user purpose, so it should be flagged as a mismatch.
The declared description says this skill creates persona packs from source materials about a person or character. The actual code does none of that. It implements local filesystem version control for an existing skill by reading meta.json, copying directories into a .versions snapshot folder, updating version numbers and timestamps, restoring snapshots, and printing history. This is a materially different primary purpose and includes undeclared file-management capabilities unrelated to persona creation. Therefore the description does not accurately represent the code.
The skill is explicitly designed to collect chats, documents, and public content to build portable persona artifacts, but it does not provide a prominent upfront privacy warning commensurate with the sensitivity of that data. In this context, users may submit intimate third-party communications and personal archives without understanding retention, repackaging, and downstream training/export consequences.
The skill explicitly encourages creating personas of friends, family, partners, and ex-partners from their chats and documents. Even with a brief 'personal use only' note, this materially facilitates impersonation, non-consensual profiling, and privacy invasion of third parties based on intimate communications.
The skill instructs the agent to retain source communications and repackage them into training data, persona files, and reusable skill artifacts. This is dangerous because it operationalizes long-term storage and transformation of sensitive personal content into assets that can be replayed, redistributed, or trained on beyond the original context of disclosure.
These instructions direct the agent to immediately save processed source material into training/raw/ while only mentioning redaction of obvious PII, without an explicit user warning that highly sensitive personal data will be persistently stored and reused. Because the skill targets chats, diaries, email, and social archives, the storage behavior materially increases privacy and consent risk, especially for third-party data.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
from datetime import datetime, timezone
from pathlib import Path
DEFAULT_BASE = Path(".claude/skills")
def _meta_path(slug: str, base_dir: Path) -> Path:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
from datetime import datetime, timezone
from pathlib import Path
DEFAULT_BASE = Path(".claude/skills")
def _meta_path(slug: str, base_dir: Path) -> Path:
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
# Check at start of Phase 3 — if this directory exists, use persona-knowledge integration
ls skills/persona-knowledge/SKILL.md 2>/dev/null && echo "persona-knowledge detected"
When detected, data flow becomes: source → persona-knowledge ingest → MemPalace + KG + wiki → persona-knowledge export → training/
The trigger list includes broad natural-language activations such as "create a persona for X," "make a skill pack for X," and "I want to talk to X as an AI," which could match ordinary user requests outside an explicit invocation context. The file does not provide negative examples or clear constraints on when these phrases should or should not activate the skill.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Tools
| Task | Tool |
| -------------------------------------------- | -------------------------------------------------------------------------------------- |
| Read any text / JSON / CSV / PDF / image | `Read` (native — use for most chat exports) |
| Search public figures / fictional characters | `WebSearch` |
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Load skills/open-persona/SKILL.md and run with the persona.json from Step 6-A:
npx openpersona create --config persona.json --output ./{slug}-skill
The skill invokes npx openpersona create without pinning a package version or verifying integrity, which can fetch and execute whatever version is current at runtime. In a skill that processes sensitive persona/training data and writes artifacts to disk, this creates a supply-chain execution risk if the package is compromised or changed unexpectedly.
Using npx openpersona install without a pinned version allows unreviewed remote code to be resolved and executed at install time. Because this skill already handles highly sensitive local data and generated persona packs, a compromised or drifting package could exfiltrate data or alter outputs.
The unpinned npx openpersona switch command has the same supply-chain risk as the other npx calls: it may execute a newer or compromised package version than intended. In context, this is risky because the command affects active persona state and may interact with local persona artifacts.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
When the user says /list-anyone:
python3 ${CLAUDE_SKILL_DIR}/scripts/skill_writer.py --action list --base-dir ./.claude/skills
Display: codename · version · last updated · subject type.
The document instructs users to execute npx openpersona create without pinning an exact package version, which allows retrieval of whatever package version is current at execution time. If the upstream package is compromised, typosquatted, or publishes a malicious update, running the command can execute attacker-controlled code on the user's machine.
The unpinned npx openpersona install command executes code from the latest resolved package version at runtime rather than a reviewed, fixed release. In this skill, the command is framed as a routine installation step, which increases the chance a user will run it directly and expose their environment to supply-chain compromise.
The npx openpersona switch {slug} instruction is another live package execution path with no version pinning, so it may fetch and run an unintended or malicious package version. Because this file is an operational reference for generating and activating persona packs, the command is likely to be followed as written, making the supply-chain risk practical rather than theoretical.
The evolution update path tells users to re-run npx openpersona create during ongoing maintenance, repeatedly reintroducing exposure to whatever package version is current at that time. Recurrent unpinned execution expands the attack window and makes later compromise more likely even if the initial setup was safe.
This code writes potentially sensitive message content from chat exports and databases to a JSON file, but there is no explicit warning in the code comments, CLI help, or user-facing output that the operation creates a new local copy of private data. Although the write is intentional, the file lacks a disclosure about the privacy impact of persisting extracted conversations to disk.
No suspicious patterns detected.