Back to skill

Security audit

Technical Blog Writing

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a technical-writing guide, but it asks users to run mutable remote installers and includes ungated public posting guidance, so it needs Review before installation.

Install only if you are comfortable using inference.sh and reviewing its installer. Prefer manual download with pinned versions and checksum or signature verification, avoid running curl-to-shell blindly, do not connect or use X posting unless you intend to publish the exact text, and treat each related skill install as a separate unpinned third-party install that should be reviewed independently.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:14
Finding

Remote Installation Script Executed Directly Through a Shell

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:290
Finding

Unpinned Third-Party Tool and Skill Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

curl ... | sh executes a remotely fetched script directly in the shell, creating a classic supply-chain and remote code execution risk if the server, transport, or distribution pipeline is compromised. Even with checksum claims elsewhere in the text, the one-line install pattern encourages execution before independent verification and is especially dangerous in a skill document that may be copied verbatim by users.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

Quick Start

bash
curl -fsSL https://cli.inference.sh | sh && infsh login

# Research topic depth
infsh app run exa/search --input '{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest-style description includes many generic trigger phrases such as "technical writing," "developer content," and "technical content," which can overlap with ordinary requests and unrelated documentation tasks. It does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a technical blog writing aid, but it includes an example for posting directly to X, which crosses from content drafting into external publication. That capability is materially more sensitive because it can cause unintended public disclosure, reputational damage, or unauthorized posting if invoked without explicit user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown includes an outbound X posting example without any warning that it publishes externally or that explicit approval is required. In an agent setting, silent or poorly signposted publication actions are dangerous because they can lead to accidental data release or user-harmful actions beyond drafting.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest frames the skill as technical blog post writing and writing conventions, not research or web search. While light research may support writing, explicitly invoking an external search app introduces a capability outside the declared writing-centric scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.