Back to skill

Security audit

Agent Architect

Security checks for vulnerabilities and agentic risk

Overview

This skill is a markdown-only architecture consultant whose behavior is mostly advisory and purpose-aligned, with one third-party setup command users should verify before running.

Before installing, treat this as an advisory planning skill. It is reasonable to use for agent architecture recommendations, but do not let an agent run `npx nia-wizard@latest` or any other setup command from the references without checking the package, publisher, and preferably pinning a reviewed version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/nia-docs.md:18
Finding

Unpinned Third-Party Package Execution Recommendation

Content
View full analysis

Vulnerability Details

File Location: references/nia-docs.md, line 18
Vulnerability Type: Unpinned third-party package execution through a mutable package tag
Risk Level: Medium

Vulnerable Code Snippet:

markdown
Nia's plugin and skill pattern is particularly relevant for coding agents. The docs distinguish heavier MCP-style integration from lighter agent-skill approaches that call Nia directly. That split is useful because it recognizes that agents need both standard interfaces and pragmatic shortcuts. The `npx nia-wizard@latest` setup flow fits this philosophy well: it gives agents and developers a first-class way to install and configure Nia-backed capabilities instead of treating remote docs as a disconnected surface. Combined, local sync, shared context, and agent skills form a practical blueprint for making current knowledge available where coding agents already work.

Technical Analysis

The documented npx nia-wizard@latest setup flow references the mutable latest package tag rather than a fixed, reviewed version. When invoked, npx can retrieve the package selected by that tag and execute its code locally. The effective code can therefore change after this Skill has been reviewed without any corresponding modification to the repository.

The project does not specify a known-good version, lockfile, integrity hash, trusted publisher identity, or inspection step. Although the command is presented descriptively rather than as a mandatory automated action, SKILL.md directs the Agent to use these references when making concrete architecture and tool recommendations. Consequently, the unsafe setup flow could be relayed to a user and executed.

Exploitation would require compromise or malicious control of the referenced package, its publisher account, or the package registry metadata controlling the latest tag.

Attack Path

  1. An attacker compromises the nia-wizard package publisher, regi ...[truncated 1217 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable tag with an explicitly reviewed version, such as npx nia-wizard@<reviewed-version>.
  2. Verify the package name, publisher identity, release provenance, and expected repository before recommending execution.
  3. Prefer a lockfile-backed installation process that records the complete resolved dependency graph.
  4. Where supported, validate registry integrity metadata, signed provenance, or a documented package checksum.
  5. Instruct users to inspect third-party setup utilities and their lifecycle scripts before running them.
  6. Run setup tools in a restricted environment with minimal filesystem access, isolated credentials, and constrained network permissions.
  7. Document an approved version-update process requiring review and testing before changing the pinned version.
  8. Clarify in the reference that the command is an optional external installation step and must not be executed automatically by the Agent.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s activation description is broad enough to trigger on many generic requests about planning, designing, or architecting AI systems, which can cause the wrong skill to activate in contexts where more specific or safer skills should handle the request. Over-broad routing increases the chance of unintended instruction injection into conversations and can degrade security posture by unnecessarily exposing users to this skill’s behavior and reference-handling logic.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation recommends executing npx nia-wizard@latest, which pulls and runs the newest published package version at install time rather than a reviewed, pinned release. In an agent-oriented skill, this is risky because users or downstream automation may copy the command directly, creating a supply-chain exposure if the package is compromised or a breaking/malicious release is published.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/nia-docs.md (reported line 14)May include surrounding context.

md
Nia positions itself as an API layer for agent context. The product is not just about hosting documentation; it is about giving coding agents current, structured access to the information they need across repositories, docs, and local files. That makes it a useful reference for this knowledge repo, because the challenge here is not simply storing markdown. The harder problem is ensuring that an agent can discover, load, and reuse the right context at the right time without every session starting cold.

One of Nia's most relevant capabilities is local sync. The docs describe workflows for syncing local repositories and other local sources so the agent-facing context is not limited to what already exists on the public web. That matters for private systems, unpublished notes, and in-progress codebases where the most important context often exists only on disk. A knowledge repository can borrow this pattern by treating local markdown, imported docs, and generated summaries as first-class sync targets instead of as disconnected artifacts.

The context-sharing model is another important idea. Nia is designed so context can be shared between teammates or between systems without requiring each agent session to rediscover the same set of references manually. In practice, that means curated context becomes an asset in its own right. For a repo like this one, the manifest and summary pages play a similar role: they turn source discovery and evaluation into persistent state.

Static analysis

No suspicious patterns detected.