Back to skill

Security audit

Find Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill is meant to find and install other skills, but it encourages broad activation plus unpinned remote CLI use and global installs that skip confirmation.

Review exact sources before installing anything found by this skill. Prefer pinned CLI versions, immutable repository refs, local installation, and visible confirmation prompts; avoid using `-g -y` unless you intentionally want a global user-level skill installed without the CLI asking again.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:25
Finding

Unpinned External Package Execution and Unattended Global Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25-30, 50, and 75-79
Vulnerability Type: Supply-chain exposure through unpinned package execution and unsafe external installation
Risk Level: High

Vulnerable Code Snippets:

markdown
**Key commands:**

- `npx skills find [query]` - Search for skills interactively or by keyword
- `npx skills add <package>` - Install a skill from GitHub or other sources
- `npx skills check` - Check for skill updates
- `npx skills update` - Update all installed skills
bash
npx skills find [query]
markdown
### Step 4: Offer to Install

If the user wants to proceed, you can install the skill for them:

```bash
npx skills add <owner/repo@skill> -g -y
text

### Technical Analysis

The skill directs the agent to execute `npx skills` without specifying an exact, reviewed package version or validating package integrity. Depending on the local npm configuration and cache state, `npx` may retrieve and execute the package from an external registry. Consequently, the code ultimately executed can change after this skill has been reviewed.

Search results can identify skills hosted in external repositories, and the installation procedure does not require an approved publisher, immutable commit identifier, checksum, signature, or source-code review. The recommended `-g -y` flags further increase exposure: `-g` installs the selected skill at user scope, while `-y` suppresses confirmation prompts. Globally installed skill instructions may subsequently be available to other projects or agent sessions.

This is a supply-chain weakness rather than evidence that the currently referenced CLI or repositories are malicious. Exploitation depends on compromise, replacement, typosquatting, or malicious publication of the npm package or a selected external skill.

### Attack Path

1. An attacker publishes a malicious package or skill, compromises 
...[truncated 1541 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an exact reviewed version, for example by using an exact npm version rather than an unconstrained npx skills invocation.
  2. Verify package integrity with a lockfile, registry integrity hash, or cryptographic signature before execution.
  3. Maintain an allowlist of approved publishers and repositories. Do not install arbitrary search results without provenance validation.
  4. Pin external skills to immutable commit hashes or signed releases rather than mutable branches or tags.
  5. Remove -y so that installation requires an explicit approval step after displaying the exact source, version, requested scope, and relevant security implications.
  6. Avoid -g by default. Prefer a project-local, isolated installation that cannot affect unrelated projects or future sessions.
  7. Download and statically inspect the selected skill and any executable scripts before installation or activation.
  8. Run discovery and installation tools in a sandbox with restricted filesystem, credential, process, and network access.
  9. Separate discovery from installation: search may be automated, but installation should require explicit user authorization for the exact immutable artifact.
  10. Define a controlled update policy. Updates should be reviewed and integrity-verified rather than applied automatically from mutable upstream sources.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description says the skill should be used for broad prompts like 'how do I do X' or general interest in extending capabilities. Such overlap with common user requests can cause unintended invocation, making the agent more likely to run discovery/install workflows when the user only wanted advice, thereby increasing exposure to the risky npx actions described below.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation conditions are ambiguous and broad, covering generic asks like 'can you do X' and vague expressions of interest. In context, this is more dangerous because the skill's prescribed behavior leads toward executing unpinned package-manager commands and offering installations, so over-triggering increases the chance of unsafe actions from ordinary conversation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning an exact package version, which means execution may resolve to whatever package version is current at runtime. That creates a supply-chain risk: a compromised upstream package, typo-squatted dependency chain, or breaking update could lead to arbitrary code execution when users search for or install skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command reference uses npx skills without an exact version, so execution depends on mutable upstream state. In a skill whose purpose is to discover and install more code, that expands supply-chain exposure and can let an attacker influence what code is executed on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The npx skills add instruction is unpinned and intended to install third-party content from GitHub or other sources. Because the executable version and downstream content are both mutable, users face compounded risk of arbitrary code execution or installation of malicious skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

An unpinned npx skills check still executes remote package code that may change over time. Even though this is a check operation, users are encouraged to trust and run mutable code from upstream without version control.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The update command runs an unpinned CLI and is specifically designed to modify installed skills, increasing the blast radius if the toolchain is compromised. A malicious or broken upstream release could trigger unsafe updates across all installed skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The workflow tells the agent to run npx skills find [query] using an unpinned package version. Because the skill may be auto-invoked for broad user requests, this can normalize frequent execution of mutable remote code in response to ordinary prompts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This example search command again relies on unpinned npx skills, encouraging users or agents to execute the latest remote package version. In the context of skill discovery, repeated examples reinforce unsafe operational defaults.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The PR review example promotes unpinned execution of a remote CLI, which could be hijacked through upstream compromise. Since the skill is framed as assisting capability extension, users may execute these commands with elevated trust and little scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This changelog search example continues the pattern of invoking an unpinned remote package. The cumulative effect is a documented workflow that repeatedly exposes users to supply-chain risk for routine discovery actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install example explicitly tells users to run npx skills add without pinning the CLI version, directly leading to installation of third-party code. This is particularly dangerous because installation is a high-trust action with potential filesystem and environment impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This line instructs installation with npx skills add <owner/repo@skill> -g -y, combining unpinned remote code execution with global installation and confirmation bypass. That substantially increases the chance of silent system-wide modification or arbitrary code execution without meaningful user review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions recommend -g -y, which performs global installation and suppresses confirmation prompts without a user-facing warning. This removes an important safety checkpoint and can silently introduce system-wide third-party code, a severe risk when combined with unpinned package execution and installation from remote sources.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Recommending npx skills init without version pinning still encourages execution of mutable upstream package code, though the action is less directly dangerous than install/update. It remains a supply-chain risk because the initializer may create files or execute setup logic on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The no-results example suggests using npx skills init unpinned, again normalizing execution of mutable remote code. While not obviously malicious, it exposes users to unnecessary upstream trust for local project scaffolding.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.