Back to skill

Security audit

VitePress Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward VitePress site generator, but users should review its dependency and deployment examples before running them.

Before installing or using this skill, confirm that you want a VitePress-based site and run its setup only in the intended project directory. For production or CI use, pin npm package versions, GitHub Actions, and Docker images, and review any workflow that receives repository write credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T08 · Insecure Dependencies

Warning
Location
scripts/init-vitepress-site.sh:22
Finding

Unpinned VitePress Dependency Executes Mutable Registry Code

Content
View full analysis
Remediation
View remediation
``` - Commit `package-lock.json` and use `npm ci` for reproducible CI and deployment installations. - Review lockfile changes before accepting dependency updates. - Use automated dependency updates with mandatory review, test, and security scanning. - Consider disabling lifecycle scripts where they are unnecessary: ```bash npm ci --ignore-scripts ``` Only use this option after confirming that the project does not require legitimate lifecycle scripts. - Run installation and builds in an isolated, least-privileged environment without unrelated credentials. ]]>

T08 · Insecure Dependencies

Warning
Location
references/deployment.md:20
Finding

GitHub Actions Workflow Uses Mutable Action Tags

Content
View full analysis
Remediation
View remediation
- uses: actions/setup-node@ - uses: peaceiris/actions-gh-pages@ ``` - Retain the release version in comments so maintainers can identify the pinned release. - Declare minimal workflow permissions explicitly, granting write access only to the deployment job or step that requires it. - Separate build and deployment jobs where practical, and provide publication credentials only to the deployment boundary. - Use automated action-update tooling that proposes reviewed SHA changes through pull requests. - Review third-party action source code and ownership before adoption. ]]>

T08 · Insecure Dependencies

Warning
Location
references/deployment.md:64
Finding

Docker Deployment Uses Mutable Base Image Tags

Content
View full analysis
Remediation
View remediation
AS build ... FROM nginx:alpine@sha256: ``` - Use automated tooling to propose digest updates through reviewed pull requests. - Scan base images and the final image for known vulnerabilities before deployment. - Build in an isolated environment without unnecessary credentials. - Use BuildKit secret mounts when build-time credentials are unavoidable; never copy credentials into image layers. - Run the deployed container as a non-root user where supported, drop unnecessary Linux capabilities, use a read-only filesystem, and avoid privileged mode or sensitive host mounts. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough to match many ordinary requests such as 'generate website' or 'create blog', which can cause this skill to activate outside its intended scope. Over-broad activation increases the chance the agent will suggest VitePress-specific setup and command execution in contexts where the user did not explicitly ask for this toolchain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to run project-initialization commands like mkdir, npm init, and package installation without warning that they create directories, write files, and modify package metadata. In an agentic setting, this can lead to unexpected filesystem and environment changes, especially if executed in the wrong directory or without explicit user confirmation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.