Back to skill

Security audit

Draco3D — 3D Geometry Compression

Security checks for vulnerabilities and agentic risk

Overview

This skill is a concise Draco3D usage guide with a disclosed package install and no hidden execution, persistence, or sensitive data handling.

Before installing, pin `draco3d` to a reviewed exact version and use a lockfile or `npm ci` for reproducible installs. The skill otherwise appears to be documentation-only and limited to Draco3D integration guidance.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned npm Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 6
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
`npm i draco3d` (WASM codec) | CDN: `gstatic.com/draco/versioned/decoders/1.5.7/`

Technical Analysis

The installation instruction does not specify an exact version of the draco3d npm package. Consequently, users following this instruction will install whichever package version currently satisfies npm's default resolution behavior. The resolved registry artifact can change after the skill has been reviewed.

This creates a supply-chain risk because a future malicious or compromised package release could introduce harmful runtime code or npm lifecycle scripts. Such scripts may execute during installation with the permissions of the user running npm. Although the referenced CDN decoder is version-pinned to 1.5.7, that pin does not protect the separate npm installation command.

No evidence indicates that the currently documented package is malicious. The vulnerability is the unsafe, mutable dependency-resolution practice.

Attack Path

  1. An attacker compromises the draco3d publishing account, npm distribution process, or a future package release.
  2. The attacker publishes a modified package version containing malicious runtime code or an installation lifecycle script.
  3. A user follows the documented npm i draco3d instruction without an exact version or reviewed lockfile.
  4. npm resolves and downloads the attacker-controlled release.
  5. Malicious lifecycle code may execute during installation, or malicious package code may execute when the application imports and uses the dependency.

Impact Assessment

Successful exploitation could execute code with the privileges of the user or automation account performing installation or running the resulting application. Depending on that account's access, the attacker could read o ...[truncated 332 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the unversioned command with an exact, reviewed release, for example: npm install --save-exact draco3d@<reviewed-version>.
  • Commit a generated lockfile containing registry URLs and integrity hashes.
  • Use npm ci in CI/CD and production build environments to enforce lockfile resolution.
  • Review package provenance, maintainers, release history, and published artifacts before upgrading.
  • Perform dependency updates through a controlled review process with security scanning and testing.
  • Where package lifecycle scripts are unnecessary, install with --ignore-scripts or enforce an equivalent package-manager policy.
  • Pin and verify all remotely hosted WASM and JavaScript assets; consider self-hosting reviewed artifacts and applying Subresource Integrity where supported.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.