Back to skill

Security audit

find-skills

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent purpose, but it can steer broad user requests into running unpinned external package commands and globally installing third-party skills with confirmation skipped.

Install only if you are comfortable with an agent recommending and potentially running external skill package commands. Before using it, prefer pinned CLI versions, review each skill source and contents, avoid `-g` and `-y` by default, and require explicit approval immediately before any install or update.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned CLI Execution and Unreviewed Global Skill Installation

Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` ```bash npx skills find [query] ``` ```markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts. ``` ### Technical Analysis The Skill instructs the Agent to execute the `skills` npm package through `npx` without specifying a reviewed package version or integrity value. Depending on local npm behavior and cache state, `npx skills` may retrieve and execute a currently published package version from an external registry. The effective CLI implementation can therefore change after this Skill has been reviewed. The CLI is then used to discover and install additional Skills from GitHub or unspecified “other sources.” The recommended installation command combines global user-level installation (`-g`) with automatic confirmation (`-y`). This makes it possible to install third-party content persistently without an interactive confirmation step or a documented source-review procedure. The project does not itself contain a malicious payload, scripts, credential access, or an implemented exfiltration mechanism. The risk arises from its unsafe supply-chain workflow and delegated trust in mutable external packages and repositories. ### Attack Path 1. An attacker publishes a malicious or compromised version of the npm package resolved by `npx skills`, compromises a repository returned by the search ...[truncated 1595 chars]
Remediation
View remediation
find ``` Maintain a documented review process before changing that version. 2. Where supported, verify registry provenance and package integrity using a lockfile, integrity hash, trusted registry configuration, and package-signing or provenance information. 3. Restrict installation sources to an explicit allowlist of reviewed owners and repositories. Do not permit arbitrary GitHub repositories or unspecified external sources by default. 4. Remove `-y` from installation commands so the user can review the exact source, version, destination, and requested changes before installation. 5. Avoid global installation by default. Prefer a project-scoped or isolated installation so an untrusted Skill cannot automatically become available across unrelated projects and sessions. 6. Before installation, retrieve the candidate into a quarantined directory and review all instruction files, scripts, manifests, dependencies, lifecycle hooks, network behavior, and requested permissions. 7. Require explicit user authorization immediately before installation. Search or discovery consent should not be treated as installation consent. 8. Execute package discovery and installation in a sandbox with restricted filesystem, network, environment-variable, and credential access. 9. Record the installed repository, immutable commit hash, Skill identifier, and reviewed content digest. Updates should require a new review rather than automatically trusting the latest upstream state. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description activates on broad phrases like 'how do I do X' and 'can you do X', which overlap with many normal user requests. Over-broad activation can cause the agent to invoke this skill in contexts where the user did not request package discovery, leading to unsolicited search/install suggestions and unnecessary exposure to external code ecosystems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'When to Use This Skill' section includes ambiguous triggers such as any specialized capability request or general desire for help in a domain. In context, this is risky because the skill then recommends commands that fetch and install third-party tooling, so false-positive activation can steer ordinary conversations toward unsafe package execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a specific version, which means execution depends on whatever package version is current at runtime. If the upstream package or dependency chain is compromised or changes behavior, users may execute unreviewed code while searching for or installing skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This reference invokes npx skills without a fixed version, allowing runtime resolution of the latest package and its transitive dependencies. That creates a supply-chain risk because a malicious or broken release could be fetched and executed automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Using npx skills without version pinning causes execution to depend on mutable upstream state rather than a reviewed artifact. In a skill whose purpose is discovering and installing more code, that increases the chance of cascading trust failures if the CLI is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This command uses an unpinned npx package, so the exact code executed may vary over time. Because the command is part of package-management guidance, exploitation could lead to arbitrary code execution in the user's environment via a compromised published package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

An unpinned npx skills invocation exposes users to package substitution or malicious updates, since no immutable version is specified. The surrounding context encourages routine use, making the risk operational rather than theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The search command relies on npx skills without version pinning, allowing unreviewed upstream code to run during simple discovery workflows. Since users may treat search as low-risk, this can normalize unsafe execution of mutable third-party code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This example search command executes a non-pinned package via npx, introducing supply-chain exposure. A compromised CLI could abuse the trust implied by this skill to run arbitrary code even before any skill is installed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Because npx skills is not pinned here, the exact executable is mutable and fetched at runtime. In a skill focused on discovering external extensions, this compounds supply-chain risk by trusting both the CLI and later-installed packages.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This unpinned npx skills example leaves users exposed to malicious or accidental upstream changes in the package they execute. The context makes it more dangerous because it is a canonical example likely to be copied verbatim.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The install command shown to users is based on an unpinned package manager CLI, which could itself be compromised before it installs the requested skill. This creates a trust-on-first-use problem with code execution from a mutable source.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line recommends npx skills add <owner/repo@skill> -g -y, combining unpinned CLI execution with global installation and confirmation bypass. That materially increases risk because a user may execute and install arbitrary code system-wide with minimal review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly recommends npx skills add <owner/repo@skill> -g -y, which installs code globally and suppresses confirmation without warning about system-wide impact, trust, or review. That lowers friction for executing third-party code with broader persistence, making accidental or malicious installation substantially more dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This package-management example uses a floating npx skills reference, so the actual executed code may change over time. Users following documentation may unknowingly run a compromised or incompatible release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The guidance here again instructs use of npx skills without version pinning, exposing users to mutable upstream code execution. Repetition across the document increases the likelihood that unsafe usage becomes standard practice.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This npx skills init example is also unpinned, so even the skill-creation workflow depends on whatever upstream version is live at execution time. That widens the attack surface to all users experimenting with the ecosystem.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.