Back to skill

Security audit

PartnerBoost Brand

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PartnerBoost API reference, but users should treat its API key and installation commands carefully.

Install only from the intended repository and prefer pinned or verified Skills CLI versions. Provide a least-privileged PartnerBoost API key, avoid placing the key in chat logs or command history, and review any agent-requested API call before sending sensitive merchant, transaction, billing, or account data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:29
Finding

Unpinned npm Package Execution in Installation Instructions

Content
View full analysis
/ ``` Anyone can install from **this repository’s address** on your Git host (GitHub `owner/repo`, a full repo URL, or another format the [Skills CLI](https://skills.sh/docs/cli) accepts). Use the `owner/repo` shown on the repo home page, for example: ```bash npx skills add OWNER/partnerboost-brand ``` Run `npx skills add --help` for flags such as `-g` / `--global` and `-a` / `--agent` (target Cursor, Claude Code, OpenCode, etc.). ``` ### Technical Analysis The documented command invokes `npx skills` without pinning the npm package to a reviewed version or integrity value. If the executable is not already available locally, `npx` can resolve and execute the package supplied by the configured npm registry. Consequently, the code executed during installation may differ from the version that was originally reviewed. Security depends on the continued integrity of the registry package, its publisher account, the user's registry configuration, and the repository identifier supplied to the command. The documentation does not specify an authoritative publisher, fixed package version, integrity hash, or repository revision. This is a supply-chain weakness rather than evidence that the current repository contains malicious code. ### Attack Path 1. An attacker compromises the package publisher, registry account, package distribution channel, or a registry used by the victim. 2. The attacker publishes or substitutes a malicious package version that exposes the expected `skills` executable. 3. A user follows the documented unpinned `npx skills add` command. 4. `npx` resolves the attacker-controlled package vers ...[truncated 965 chars]
Remediation
View remediation
add / ``` 2. Replace placeholders in the primary installation example with the exact authoritative repository owner and name. 3. Document the official npm package name, verified publisher, and expected registry. 4. Where supported, verify the package checksum, provenance, or registry signature before execution. 5. Pin the imported Skill to a reviewed commit hash or signed release rather than an unrestricted moving branch. 6. Advise users to inspect the resolved package and repository identity before approving execution. 7. Run installation with an unprivileged account and a minimal environment that does not expose unrelated secrets. 8. Keep the pinned version under periodic review and update it only after validating the new release. ]]>

T08 · Insecure Dependencies

Warning
Location
README.zh-CN.md:29
Finding

Unpinned npm Package Execution in Localized Installation Instructions

Content
View full analysis
/ ``` 他人直接用这个 Skill **所在仓库**在代码托管平台上的地址即可安装(GitHub 的 `owner/repo`、完整仓库 URL 等,以 [Skills CLI](https://skills.sh/docs/cli) 支持的格式为准)。把 `/` 换成仓库主页上显示的「所有者/仓库名」,例如: ```bash npx skills add OWNER/partnerboost-brand ``` 更多参数见 `npx skills add --help`(如 `-g` / `--global`、`-a` / `--agent` 指定 Cursor、Claude Code、OpenCode 等目标)。 ``` ### Technical Analysis The localized documentation reproduces the unpinned `npx skills` command. No reviewed package version, integrity value, authoritative publisher identity, or fixed repository revision is specified. The command can therefore execute a package version resolved at installation time rather than a version whose contents are fixed by this repository. The resulting trust boundary includes the npm registry, the package publisher, the user's registry configuration, and the repository address selected by the user. Compromise or substitution at any of those points can convert the installation step into arbitrary local code execution. This finding concerns unsafe installation guidance; no malicious executable code was found in the audited repository itself. ### Attack Path 1. An attacker gains control of, impersonates, or substitutes the package resolved for the `skills` executable. 2. The attacker publishes a malicious version or redirects resolution through an untrusted registry. 3. A user copies the unpinned command from the localized README. 4. `npx` retrieves and executes the attacker-controlled package. 5. The package runs under the user's account and can interact with resources available to that process. 6. It can steal accessible environment secrets, modify Agent or Skill f ...[truncated 579 chars]
Remediation
View remediation
add / ``` 3. Identify the authoritative npm publisher, package registry, repository owner, and repository name. 4. Pin installation to a reviewed commit or signed release where the tooling permits it. 5. Add package provenance, signature, or checksum verification instructions. 6. Warn users not to install from lookalike owners, repositories, packages, or unofficial registries. 7. Recommend installation from an unprivileged account with unrelated secrets removed from the process environment. 8. Review and update the pinned release only after its package contents and publisher provenance have been verified. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (13)

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The README instructs users to run npx skills add without pinning an exact package version. Because npx resolves and executes the current package from the registry, a compromised maintainer account, malicious dependency update, or unexpected breaking release could cause unreviewed code to run on the user's machine during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

This example again tells users to execute npx skills add with no version pin, which creates a supply-chain risk by trusting whatever version is latest at execution time. In a skill ecosystem where users are already being guided to install remote content from repositories, that dynamic execution path increases exposure to package hijacking or malicious updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
82% confidence
Finding

Referencing npx skills add --help without a pinned version still triggers the same trust-on-first-use problem: npx may fetch and run the newest published package. Although this specific command is for help text, it still executes package code and therefore carries supply-chain execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The repeated unpinned npx skills guidance extends the same package-execution risk throughout the README. Given this skill manages an API key for merchant-side PartnerBoost access, compromise during setup could expose credentials or alter installed skill behavior in a way that affects billing, transactions, or account data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs use of an authenticated external API that can access merchant transactions, performance, billing, and account information, but it does not warn users that prompts or supplied business data may be transmitted to a third-party service. In an agent setting, this omission can lead to unintentional disclosure of sensitive commercial or financial data because users may not realize the action leaves the local environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
All WebUI APIs follow this pattern:

- **GET**: `curl -s -H "X-Api-Key: $PARTNERBOOST_API_KEY" "https://app.partnerboost.com/a/{controller}/{action}?param1=value1&param2=value2"`
- **POST**: `curl -s -X POST -H "X-Api-Key: $PARTNERBOOST_API_KEY" -H "Content-Type: application/json" -d '{"key":"value"}' "https://app.partnerboost.com/a/{controller}/{action}"`

## Response Format

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file header presents the English README as the default with a separate Simplified Chinese link, which constitutes a language preference embedded in the documentation. The policy only permits this when the skill offers a language choice or clearly justifies the locale constraint; this file does not explain why English is the default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

Line 1 marks this file as Simplified Chinese, and the body content is entirely in that language. Although an English link is present, the file itself fixes the locale rather than explicitly offering language selection within the skill instructions, which can be interpreted as a locale constraint without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README instructs agents to use an API key to call merchant-side APIs for transactions, performance, billing, and account operations, but it does not prominently warn that sensitive business/account data may be transmitted or that actions could affect operational records. In an agent-skill context, missing safety and scope warnings increase the chance of accidental high-privilege use, data exposure in logs, or unintended business actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.