Back to skill

Security audit

Agent Device

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed mobile automation guide with expected logging and setup cautions, not hidden or destructive behavior.

Before installing, prefer a trusted preinstalled agent-device binary or pin and verify the npm package version. Use the skill only against devices, simulators, and apps you are authorized to automate, keep logging off unless debugging, and review or delete logs under ~/.agent-device because they may contain sensitive app data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:94
Finding

Unauthenticated npm Package Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 94-95
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

markdown
- Prefer a preinstalled `agent-device` binary over on-demand package execution.
- If install is required, pin an exact version (for example: `npx --yes agent-device@<exact-version> --help`).

Technical Analysis

The documented fallback invokes npx to retrieve and execute the agent-device package from the configured npm registry. Although pinning an exact version reduces version drift, it does not independently authenticate the expected package contents or protect against registry compromise, maintainer-account compromise, malicious publication of the selected version, or registry configuration that resolves to an untrusted source.

The --yes option suppresses the normal installation confirmation. Package lifecycle hooks and package runtime code may execute with the permissions of the user running npx. The command therefore crosses a supply-chain trust boundary without requiring integrity verification or provenance validation.

Attack Path

  1. An attacker compromises the npm package, its publisher account, the configured registry, or the dependency resolution path.
  2. A user or agent follows the documented installation fallback.
  3. npx --yes downloads the selected package without an interactive confirmation step.
  4. npm lifecycle code or the invoked package entry point executes locally.
  5. Malicious code operates with the invoking user's privileges and can access resources available in that environment.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user invoking npx. Depending on the host environment, the affected scope could include project files, user-readable credentials and configuration, mobile automation artifacts under ~/.agent-device, connected ...[truncated 293 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer an already installed binary obtained through a documented, trusted distribution channel.
  2. Publish an explicit approved package version rather than leaving version selection to the operator.
  3. Require verification of the npm registry origin, package integrity hash, signatures, and available provenance attestations before execution.
  4. Avoid --yes so unexpected installation or resolution behavior remains visible to the operator.
  5. Install and inspect the package without executing lifecycle scripts where practical, then run it only after verification.
  6. Execute installation and first use in an isolated, least-privilege environment without production credentials or sensitive connected devices.
  7. Document a verified binary checksum or signed release process and provide a secure update procedure.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/logs-and-debug.md (reported line 10)May include surrounding context.

md
- Default app logs are stored under `~/.agent-device/sessions/<session>/app.log`.
- Replay scripts saved with `--save-script` are written to the explicit path you provide.
- Log files may contain sensitive runtime data; review before sharing and clean up when finished.
- Use `AGENT_DEVICE_APP_LOG_REDACT_PATTERNS` to redact sensitive patterns at write time when needed.

## Retention and Cleanup

Static analysis

No suspicious patterns detected.