Security checks for vulnerabilities and agentic risk
Overview
This is a disclosed online skill installer, but it uses mutable npm commands and remote downloads without strong verification.
Install only if you trust the skill4agent npm package and service. Prefer a pinned, reviewed CLI version, inspect downloaded skills before activation, and avoid running the installer in projects or shells that expose sensitive credentials.
Insecure DependenciesIntroduces malicious components through unsafe dependency sources
Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)
T08 · Insecure Dependencies
Warning
Location
SKILL_EN.md:7
Finding
Unpinned Third-Party CLI Execution and Unverified Remote Skill Installation
Content
View full analysis
-j
# Control the number of returned results (recommended to use -j for JSON format output)
npx skill4agent search -j -l
```
From `SKILL_EN.md:84-97`:
```bash
# Install original skill
npx skill4agent install
# Install translated skill
npx skill4agent install --type translated
```
```text
https://skill4agent.com/api/download/?type=
```
The corresponding commands and dependencies are also present in `SKILL.md` at the listed line ranges.
### Technical Analysis
The Skill recommends invoking `npx skill4agent` without specifying an exact package version or integrity constraint. Depending on the local npm environment, `npx` can retrieve the current package release from the npm registry and execute its lifecycle or CLI code with the permissions of the user running the agent. Consequently, the effective executable code can change after this Skill has been reviewed.
The installation workflow also obtains Skill archives from a mutable external API and places their contents under `.agents/skills/`. The documentation does not require a cryptographic signature, trusted checksum, immutable artifact identifier, or mandatory local inspection for every downloaded Skill. It instead relies substantially on server-supplied `script` metadata t
...[truncated 2182 chars]
Remediation
View remediation
-- skill4agent ...`.
- Do not use version ranges for security-sensitive execution.
2. **Verify package integrity**
- Record and verify the expected npm artifact integrity hash.
- Use a lockfile or equivalent immutable dependency manifest where the execution environment permits it.
- Re-audit the package before updating the pinned version.
3. **Authenticate downloaded Skill artifacts**
- Require signed archives or checksums distributed through an independently authenticated channel.
- Bind verification data to a specific Skill version or immutable artifact identifier.
- Reject downloads when signatures, checksums, expected identities, or versions do not match.
4. **Stage and inspect downloads**
- Download and extract remote Skills into an isolated staging directory rather than directly into an active Skill directory.
- Validate archive paths to prevent absolute-path and directory-traversal extraction.
- Reject symbolic links, unexpected executable files, and files outside an explicit allowlist.
- Perform local static review of all scripts and instruction files before activation, regardless of API-provided safety metadata.
5. **Require explicit authorization**
- Present the source, exact version, checksum, included files, scripts, and requested destination to the user.
- Obtain explicit consent before installing or executing any remotely retrieved component.
6. **Restrict execution privileges**
- Run package and archive inspection in a sandbox with minimal filesystem and network access.
- Do not expose unrelated credentials or sensitive environment variables to the CLI.
- Restrict write access to a dedicated staging area until verification is complete.
7. *
...[truncated 269 chars]
The skill instructs users to run npx skill4agent without pinning an exact package version, which allows whatever version is current in the npm registry at execution time to be fetched and run. Because this skill is explicitly for searching, reading, and installing other skills, it encourages repeated execution of remote code in a high-trust workflow, increasing supply-chain risk if the package is compromised, typo-squatted, or maliciously updated.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding
This command example uses unpinned npx skill4agent, causing npm to resolve and execute the latest available package version at runtime. That creates a supply-chain execution path directly from documentation, which is especially risky because the command is presented as a normal search operation and may be run without additional scrutiny.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding
The documentation again instructs running an unversioned npm package via npx, which means the executed code is not stable or auditable over time. An attacker who gains control of the package or its distribution path could deliver arbitrary code to anyone following the skill instructions.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
This read example runs npx skill4agent without a fixed version, introducing the same remote-code execution and supply-chain exposure during a seemingly read-only action. The context makes it more dangerous because users may assume 'read' is low risk, while npx still downloads and executes package code locally.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
The translated-content read command uses an unpinned package reference, so the actual code run can change over time without review. Because the skill is a package-discovery and installation helper, compromise here could tamper with downstream recommendations or installations and mislead users about other skills' safety.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding
The install workflow invokes npx skill4agent install without version pinning, which is the most security-sensitive case because it both executes mutable package code and then installs additional content. A compromised package could run arbitrary commands, alter local files, or install malicious skills while appearing to follow the documented process.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding
This translated-skill install example repeats the unpinned npx execution pattern in a privileged workflow that writes content into the local project. The surrounding skill context increases danger because it normalizes fetching code from external registries and installing third-party skills, compounding supply-chain and trust-boundary risks.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding
The manifest description states "Support by Chinese," which imposes a language preference in the skill description rather than offering language choice. The policy for this review requires flagging language or locale constraints unless the skill explicitly offers user choice or clearly justifies the constraint.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
The skill instructs users to execute npx skill4agent without pinning a specific package version. Because npx may fetch the latest published package at runtime, a compromised maintainer account, malicious new release, or dependency hijack could result in arbitrary code execution on the user's machine during search/read/install operations. This skill is especially sensitive because it explicitly encourages installing third-party skills, increasing the trust chain and execution surface.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
This command again invokes npx skill4agent without a pinned version, allowing execution of whatever version is current in the registry at the time of use. That creates a supply-chain execution risk where a malicious or tampered package could run arbitrary code before or during the search operation.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
The unpinned npx invocation here has the same supply-chain risk: the command may download and execute an unexpected package version from npm. In a skill whose purpose is to discover and install more external content, that risk is amplified because users may trust the workflow and run it repeatedly.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
Using npx skill4agent read ... without an exact version exposes users to arbitrary code execution through npm package substitution or malicious updates. Even though the operation appears read-only, the package itself executes locally and can perform any action available to the current user.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
This translated-read command also relies on unpinned npx, so the same supply-chain execution issue applies. The apparent safety of a read operation may mislead users into underestimating that they are still executing arbitrary npm-delivered code locally.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding
The install workflow asks users to run an unpinned npx skill4agent install ..., which is particularly dangerous because it combines local code execution from npm with downloading and installing additional third-party skill content. A compromised package could silently alter files, exfiltrate data, or plant persistence while appearing to perform a normal install.
Content
No source excerpt is available for this finding.
Rp1
Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding
This translated install command repeats the same unpinned npx pattern, enabling arbitrary code execution via malicious package updates or registry compromise. Because it performs installation into local project directories, exploitation could directly modify repository contents or implant malicious skill files.