Back to skill

Security audit

用于自动切换项目中适合的node 版本

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Node version helper, but it automatically runs an unverified remote installer and changes the local developer environment without a clear consent gate.

Review before installing. This skill can be useful for Node projects, but only run it if you are comfortable with it downloading and executing the nvm installer and installing Node versions on your machine. Prefer manually installing nvm from a trusted source first, then using the script only for version switching, or require a revised version that verifies downloads and asks before installation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/nvm-auto-switch.sh:54
Finding

Unverified Remote NVM Installer Is Piped Directly to Bash

Content
View full analysis

Vulnerability Details

File Location: scripts/nvm-auto-switch.sh, line 54
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash

Technical Analysis

When NVM is unavailable, the script downloads an installation script from raw.githubusercontent.com and immediately pipes the response into Bash. The downloaded content is not saved for inspection, and its checksum or cryptographic signature is not verified before execution. The command also lacks fail-closed options such as --fail, meaning an unexpected HTTP response could be passed to the shell.

The URL refers to the established nvm-sh/nvm repository and pins version tag v0.39.7, which reduces accidental version drift. However, a mutable tag is not a cryptographic integrity control. The effective code executed by the Skill remains dependent on externally delivered content and could change after the packaged Skill has been reviewed.

Automatic NVM installation supports the Skill's declared functionality, but executing unverified network content is not the minimum-risk mechanism required to provide that functionality. The payload runs with all permissions of the user invoking the Skill.

Line 63 also displays the same unsafe installation command after an installation failure:

bash
echo "Install command: curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash"

This second occurrence does not execute the command itself, but it encourages users to repeat the unsafe installation pattern manually.

Attack Path

  1. A user invokes scripts/nvm-auto-switch.sh for a project containing an engines.node requirement.
  2. The script determines that the nvm command is unavailable.
  3. An attacker compromises a relevant delivery component, such as the upstream repository or account, the referenced tag, or the trus ...[truncated 1073 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash execution pattern.
  2. Prefer installation through a trusted operating-system package manager where supported.
  3. If downloading the upstream installer is necessary:
    • Use strict transport and error handling, such as curl --fail --show-error --location --proto '=https'.
    • Download the installer to a securely created local file instead of piping it to a shell.
    • Pin and verify a trusted cryptographic checksum or upstream signature before execution.
    • Abort on any download or verification failure.
    • Display the source, version, and verification result to the user.
    • Obtain explicit user confirmation before executing the verified installer.
    • Remove the temporary installer safely afterward.
  4. Replace the line 63 guidance with verified, non-pipelined installation instructions.
  5. Consider making NVM installation an explicit prerequisite and exiting with safe manual guidance when it is absent.
  6. Document that remote installation runs code with the invoking user's privileges and must not be performed from an unverified source.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior understates key security-relevant actions: automatic network download, installation of nvm, and execution of installer scripts. A description/behavior mismatch is dangerous because users may consent to a version-check helper without realizing it can fetch and execute remote code or alter the local runtime environment.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The pipeline into bash is the dangerous mechanism that turns remote content retrieval into immediate code execution. This chaining removes opportunities for validation or review and makes any compromise of the fetched script equivalent to arbitrary command execution on the host.

Content

Scanner excerpt · scripts/nvm-auto-switch.sh (reported line 54)May include surrounding context.

sh
# Download and install nvm
    echo "Downloading nvm..."
    curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
    
    # Load nvm
    export NVM_DIR="$HOME/.nvm"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly instructs users to run shell scripts that inspect the environment, install software, download components, and switch Node versions, but it declares no tool scope or permission boundaries. That omission increases the chance an agent or user will invoke shell-capable behavior without an explicit trust/consent model, which is risky for a skill that performs installation and system modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill says it will automatically install nvm and Node-related components, but it does not present a prominent warning or consent gate for those download and installation actions. Silent or implied installation behavior is risky because it changes the system state and may execute untrusted or unaudited remote code paths.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest states the skill supports Windows, macOS, and Linux, but this file is a Bash script using Bash-specific features such as BASH_SOURCE, POSIX shell syntax, and sourcing ~/.nvm/nvm.sh. It also assumes the Unix nvm installer and home-directory layout, which does not match native Windows execution or nvm-windows behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script automatically downloads and executes a remote installer without confirmation, integrity verification, or local review. If the network path, hosting account, upstream repository, or fetched content is compromised, arbitrary shell commands will run on the user's machine during normal skill use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing natural-language content in the skill file is written in Chinese, with no indication that this is a region-specific skill or that users may choose another language. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description suggests accurate detection of the project's Node.js version requirement, but the code uses grep/cut/sed on raw JSON and strips the version expression down to digits, ultimately matching only the major version. This can diverge from the actual engines constraint semantics such as ranges, exact versions, unions, or prerelease constraints.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching a shell script from the internet and piping it directly to bash gives remote content immediate execution privileges. In a developer environment, that can lead to full user-level compromise, credential theft, persistence, or tampering with source code and toolchains.

Content

Scanner excerpt · scripts/nvm-auto-switch.sh (reported line 54)May include surrounding context.

sh
# Download and install nvm
    echo "Downloading nvm..."
    curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
    
    # Load nvm
    export NVM_DIR="$HOME/.nvm"

External Script Fetching

Low
Category
Supply Chain
Confidence
15% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/nvm-auto-switch.sh (reported line 63)May include surrounding context.

sh
# Check if installation succeeded
    if ! check_nvm; then
        echo "Error: nvm installation failed, please install manually"
        echo "Install command: curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash"
        exit 1
    fi

Static analysis

No suspicious patterns detected.