Back to skill

Security audit

Skill Composer

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate workflow-orchestration helper, but it requests broad write and command authority without clear user controls.

Review this before installing if you expect a planning-only helper. The skill should be limited to read-only planning unless you explicitly approve file writes, shell commands, retries, fallback skills, and the declared model choice. Ask the publisher to document permissions, add confirmation gates, fix the dependency graph loop, and refresh development dependencies.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.js:130
Finding

Infinite Loop in Dependency Scheduling Enables Denial of Service

Content
View full analysis

Vulnerability Details

File Location: src/index.js, lines 130–149
Vulnerability Type: Improper validation of cyclic or unsatisfiable dependency graphs
Risk Level: Medium

Vulnerable Code

javascript
while (remainingNodes.length > 0) {
  const currentLevel = remainingNodes.filter(node => {
    const deps = graph[node];
    return deps.every(dep => visited.has(dep));
  });
  
  if (currentLevel.length > 0) {
    groups.push(currentLevel);
    currentLevel.forEach(node => visited.add(node));
  }
  
  remainingNodes = remainingNodes.filter(node => !visited.has(node));
}

return groups;

Technical Analysis

identifyParallelGroups() repeatedly searches for dependency-graph nodes whose dependencies have already been visited. It does not detect cases in which no remaining node can be scheduled.

If the graph contains a cycle, self-dependency, or reference to a nonexistent node, currentLevel can remain empty. In that state:

  1. No node is added to visited.
  2. The contents of remainingNodes do not change.
  3. The loop condition remains true indefinitely.

Because this is a synchronous loop, it blocks the Node.js event loop and continuously consumes CPU. The public orchestrate() function passes caller-supplied subtasks into this logic without validating dependency indices or verifying that the graph is acyclic.

Attack Path

  1. An attacker or untrusted upstream component supplies subtasks containing cyclic dependencies:

    javascript
    const subtasks = [
      { name: 'A', type: 'analysis', dependsOn: [1] },
      { name: 'B', type: 'writing', dependsOn: [0] }
    ];
    
  2. The application calls:

    javascript
    orchestrate(subtasks, skillMapping);
    
  3. buildDependencyGraph() accepts the dependency relationships without validation.

  4. identifyParallelGroups() cannot find a node whose dependencies h ...[truncated 881 chars]

Remediation
View remediation

Remediation Suggestions

  1. Validate every subtask before graph construction:

    • Require dependsOn to be an array.
    • Require each dependency to be an integer.
    • Reject negative or out-of-range indices.
    • Reject direct self-dependencies.
  2. Detect cyclic graphs with a standard topological-sorting algorithm, such as Kahn's algorithm or depth-first search with node states.

  3. Add an explicit progress guard to the existing loop:

    javascript
    if (currentLevel.length === 0) {
      throw new Error(
        'Dependency graph contains a cycle or an unsatisfied dependency'
      );
    }
    
  4. Return a controlled validation error instead of continuing execution when the graph is invalid.

  5. Add automated tests covering:

    • Two-node and multi-node cycles.
    • Self-dependencies.
    • References to nonexistent nodes.
    • Negative, fractional, string, and null dependency values.
    • Valid disconnected directed acyclic graphs.
  6. Where this function is exposed through a service, enforce input-size limits and execution timeouts as defense-in-depth controls.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Known Vulnerable Dependency: brace-expansion==2.0.3 — 3 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro); CVE-2026-69152 (brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-1)

High
Category
Supply Chain
Confidence
95% confidence
Finding

brace-expansion 2.0.3 has multiple reported denial-of-service issues involving exponential expansion and memory exhaustion. Even though it is in the dependency tree for development tooling, ReDoS/expansion bombs are commonly reachable when attacker-controlled glob-like patterns or brace expressions are processed, making this a credible vulnerability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.2 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
86% confidence
Finding

browserslist 4.28.2 is flagged for crash/prototype write and unbounded memory growth issues when handling untrusted stats or distinct queries. In this file it is part of the dev dependency chain, so the main exposure is build/test tooling rather than production execution, but if CI or automation ingests attacker-controlled configuration or stats data the impact can include denial of service and potentially unsafe object mutation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==3.14.2 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

js-yaml 3.14.2 has several CPU-exhaustion issues triggered by crafted YAML structures such as merge-key chains and omap resolution. Although present only in the development dependency graph here, parsing untrusted YAML in automation, configuration handling, or test tooling can allow an attacker to tie up CPU and disrupt pipelines.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The maintainer value includes the phrase "王的奴隶", which is natural-language content that can be read as degrading or inappropriate organizational text in a published skill listing. This is a policy-quality issue because public-facing metadata should avoid offensive or coercive phrasing unless clearly justified, and no such context is provided here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill declares powerful tools including Write, Bash, and Exec for an orchestration role, but the description does not warn users that orchestration may trigger file modification or command execution. In a meta-skill that coordinates other skills, this omission is dangerous because users may interpret high-level planning requests as safe analysis while the skill can enable state-changing actions across multiple steps.

Content

No source excerpt is available for this finding.

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- Write
  - Bash
  - Exec
model: sonnet
---

# Skill Composer - 技能编排师

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The FAQ states that on execution failure the skill may automatically retry or switch to fallback skills, but it does not warn that those retries/fallbacks may perform additional commands, writes, or other side effects. In an orchestration engine, silent retries and alternate-skill execution expand the action surface and can multiply unintended or unauthorized operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The task decomposition logic only matches Chinese keywords such as '分析', '报告', and '优化', which means users providing equivalent tasks in other languages may not receive the intended behavior. This is a natural-language policy concern because the file embeds a language-specific constraint without offering a language/locale choice or documenting an opt-in.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @babel/core==7.29.0 — 1 advisory(ies): CVE-2026-49356 (@babel/core: Arbitrary File Read via sourceMappingURL Comment)

Low
Category
Supply Chain
Confidence
82% confidence
Finding

@babel/core 7.29.0 is flagged for an arbitrary file read via sourceMappingURL parsing. In this lockfile it is only a devDependency transitively used by Jest/Babel tooling, so exploitability is limited to build/test workflows that process untrusted JavaScript sources, but it is still a real dependency risk rather than a false positive.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: baseline-browser-mapping==2.10.16 — 1 advisory(ies): CVE-2026-45819 (baseline-browser-mapping process termination on invalid input causes denial of s)

Low
Category
Supply Chain
Confidence
74% confidence
Finding

baseline-browser-mapping 2.10.16 is reported vulnerable to process termination on invalid input, which is a denial-of-service condition. This appears in the dev toolchain via browserslist and is unlikely to affect runtime behavior of the skill, but the dependency issue itself is plausible and should be treated as genuine.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest description is written in Chinese ('L2 编排层 - 智能技能编排引擎') with no indication that the skill supports multiple languages or that Chinese is a required locale. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 29)May include surrounding context.

json
]
  },
  "devDependencies": {
    "jest": "^30.3.0"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill names and task strings in this test file are exclusively in Chinese, which suggests the skill behavior and matching logic may be tied to a specific language. The file does not indicate that users can choose another language or that this locale restriction is intentional and documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.