Back to skill

Security audit

领导模块

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow helper for coordinating sub-agents, with no hidden payloads found, but users should understand its persistence and install-supply-chain tradeoffs.

Install only from a trusted, versioned source when possible, avoid global installation unless you need it, and review the AGENTS.md rules before adding them because they persistently change how the agent dispatches longer tasks. Expect a local memory/multi-thread-tasks.json file to store task metadata and note that task state may be deleted after one day.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:105
Finding

Unpinned npm CLI Execution Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:105-106; duplicated in README.md:48-49
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable code in SKILL.md:

bash
npx skills add multi-thread-dialogue
# or
npx skills add multi-thread-dialogue -g

Duplicated vulnerable code in README.md:

bash
npx skills add multi-thread-dialogue
# or globally
npx skills add multi-thread-dialogue -g

Technical Analysis

The installation instructions invoke the skills npm CLI through npx without specifying a package version or verifying package integrity. If the package is not already available locally, npx can retrieve and execute the currently published package from the configured npm registry.

Consequently, the code executed during installation is not fixed to the version reviewed in this audit. A compromised maintainer account, malicious replacement release, registry configuration attack, or other supply-chain compromise could cause a different package payload to run. The documentation also does not provide a checksum, lockfile, verified publisher identity, or other mechanism that binds the npm package to the declared GitHub project.

The global installation variant (-g) increases the scope because it can place package files or commands in globally configured npm locations. The exact permissions depend on the user's npm and operating-system configuration.

Attack Path

  1. An attacker compromises the publication channel or maintainer account for the unpinned skills npm package, or causes the victim's configured registry to resolve the package to an attacker-controlled release.
  2. The attacker publishes a malicious package version or modifies executable installation behavior.
  3. A user follows the documented command:
    bash
    npx skills add multi-thread-dialogue
    
  4. npx resolves and downloads the current package version rather th ...[truncated 1122 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI package to a specifically reviewed version:
    bash
    npx --yes skills@<audited-version> add multi-thread-dialogue
    
  2. Verify the exact package name, registry namespace, publisher identity, and provenance before recommending it.
  3. Publish and document an integrity checksum or signed provenance record that allows users to verify the retrieved artifact.
  4. Prefer a lockfile-backed local development dependency over ad hoc retrieval and execution through an unpinned npx command.
  5. Avoid recommending global installation by default. If global installation is necessary, explain the affected directories and explicitly state that the command must not be run with elevated privileges.
  6. Provide a non-executing manual installation method, such as downloading a versioned release archive, verifying its checksum or signature, inspecting its contents, and then copying the required files.
  7. Keep SKILL.md and README.md synchronized so both documents use the same hardened installation procedure.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that task state is auto-deleted after 1 day but does not clearly warn users about potential loss of task history or in-progress coordination data. In a multi-thread dialogue skill that tracks background tasks and interruption state, silent expiry can lead to lost work, operator confusion, or unsafe decisions made from incomplete status information.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to execute npx skills add multi-thread-dialogue without pinning a specific package version. This can cause users to fetch and run whatever version is latest at install time, increasing supply-chain risk if the package is compromised or a breaking/malicious update is published. In the context of an agent skill, install commands are especially sensitive because they directly lead users to execute remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The global install example also uses npx skills add multi-thread-dialogue -g without a pinned version, leaving users exposed to unreviewed upstream changes at execution time. Global installation can increase blast radius because any malicious or compromised package content may affect a broader environment than a local install.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation describes automatic deletion of tasks after 1 day to free resources, but does not warn users about potential data loss or clarify exactly what is deleted. In a multi-agent/task-tracking context, silent cleanup can remove records needed for recovery, auditing, or user expectations, making the behavior more dangerous than a purely informational note.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The installation command uses npx skills add multi-thread-dialogue without pinning a specific package version, which can cause users to fetch and execute whatever version is current at install time. That creates a supply-chain risk: a compromised or unexpectedly changed upstream package could run arbitrary code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The global install variant also relies on unpinned npx skills add multi-thread-dialogue -g, so it has the same supply-chain exposure as the non-global command. Because global installation may affect a broader environment, compromise here could have wider persistence or impact on the user's system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written entirely in Chinese, which creates an implicit language requirement without offering an alternative language or stating that the skill is region-specific. This can violate language/locale policy when users are not given an opt-in or choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The installation steps create memory/multi-thread-tasks.json on disk without prominently warning that persistent local state will be stored. While not directly code-execution related, undisclosed persistence can surprise users, leak workflow metadata, and create privacy or cleanup issues in shared environments. The skill context makes this somewhat more relevant because task files may contain operational state about user requests and sub-agent activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs users to create and write memory/multi-thread-tasks.json in the workspace but does not clearly warn that it will modify the filesystem. While the action is simple and appears operational rather than malicious, undocumented writes can surprise users, overwrite existing state, or conflict with repository contents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.