Back to skill

Security audit

Pi Tui

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small documentation-only guide for using a terminal UI npm package, with a normal but unpinned install instruction users should treat carefully.

Before installing, prefer pinning a reviewed package version, using a lockfile, and inspecting npm package scripts in an isolated or least-privileged environment. The skill content itself is documentation-only and does not show hidden behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party npm Dependency Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 10
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
Install: `npm install @earendil-works/pi-tui`

Technical Analysis

The installation command does not specify an exact package version. Consequently, npm dynamically resolves the package from the configured registry when the command is run. The project does not include a lockfile, integrity hash, vendored dependency, or package-provenance verification procedure that would bind installation to a previously audited artifact.

npm packages can run lifecycle scripts during installation. If the publisher account, package, registry, or local registry configuration is compromised, a malicious release could execute code with the privileges of the user running npm. The audit found no evidence that the currently referenced package is malicious; the vulnerability is the unsafe, mutable dependency resolution process.

Attack Path

  1. An attacker compromises the package publisher, the npm distribution channel, or a registry used by the victim.
  2. The attacker publishes or substitutes a malicious version of @earendil-works/pi-tui.
  3. A user or agent follows the instruction in SKILL.md and runs the unpinned installation command.
  4. npm resolves the attacker-controlled release because no exact reviewed version or integrity constraint is specified.
  5. Malicious package lifecycle scripts may execute during installation, or malicious package code may execute when imported by the application.

Impact Assessment

Successful exploitation could provide arbitrary code execution within the security context of the user performing the installation or running the consuming application. This may expose files, environment variables, developer credentials, source code, and network resources accessible to that account. The package would not inh ...[truncated 428 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable installation instruction with an exact, reviewed version, for example npm install --save-exact @earendil-works/pi-tui@<reviewed-version>.
  2. Commit an npm lockfile in consuming projects and use npm ci in automated environments to enforce locked dependency versions and integrity metadata.
  3. Verify the package publisher, registry source, provenance attestations, and package contents before approving upgrades.
  4. Configure automated dependency updates to require security review and CI validation rather than silently adopting new releases.
  5. Consider disabling lifecycle scripts during initial inspection with npm install --ignore-scripts where compatible, and explicitly review any required scripts before enabling them.
  6. Run dependency installation and builds under a least-privileged account in an isolated CI environment without unnecessary secrets or host filesystem access.
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: pi-tui
description: Pi TUI — Terminal UI framework with differential rendering + synchronized output for flicker-free interactive CLIs. 
---

# Pi TUI

Component-based architecture (TUI/Container/Box/Text/TruncatedText/Input/Editor/Markdown/Loader/CancellableLoader/SelectList/SettingsList/Spacer/Image), overlay system, IME support, autocomplete, Kitty keyboard protocol. Differential rendering TUI framework.
Install: `npm install @earendil-works/pi-tui`

## Use Cases

Use when building terminal UIs, interactive CLI apps, TUI editors, terminal select lists/settings panels, terminal Markdown rendering

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
- Autocomplete/key detection → `references/autocomplete.md`

Static analysis

No suspicious patterns detected.