T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Global Installation of an Executable npm Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears purpose-built for Kyndlo event work, but it gives an agent broad live-system authority with under-scoped remote instructions and destructive/admin commands.
Install only if you trust the Kyndlo CLI package, the Kyndlo dashboard administrators, and the token permissions. Prefer a least-privilege token, review dashboard rules before batches, avoid pasting secrets into chat or logs, and do not use the admin/update/delete examples unless you explicitly intend those live changes.
SKILL.md:14Unpinned Global Installation of an Executable npm Dependency
SKILL.md:116Untrusted Remote Dashboard Content Is Adopted as Mandatory Agent Instructions
SKILL.md:258Untrusted Values Are Interpolated into Shell Command Templates
Including gokyn event delete <eventId> gives the skill destructive authority that is unnecessary for creating or validating events from campaign tasks. If followed by an agent or triggered through prompt confusion, it could delete legitimate production data irreversibly or at scale.
The invocation guidance uses broad phrases like 'create events' or 'generate events', which can overlap with ordinary conversation and unintentionally trigger this powerful workflow. Because the skill can claim tasks, create records, and alter system state, ambiguous activation increases the risk of unintended execution.
The skill directs the agent to execute commands immediately without first asking the user anything, enabling autonomous stateful actions before fresh confirmation. In a skill that can claim tasks, create events, and modify backend records, this weakens human oversight and increases the risk of unintended operations.
Action: Run this command immediately — do not ask the user anything first.
gokyn whoami --json
The skill presents itself as a tightly scoped event-creation and validation workflow, but later exposes unrelated administrative powers including state registration, campaign seeding, event updates, and deletion. This scope expansion violates least privilege and can cause an invoking agent or user to perform destructive or admin-only actions that were not justified by the skill’s stated purpose.
State registration and campaign seeding are bootstrap/administrative functions unrelated to ordinary event creation and validation. Their presence broadens the operational authority of the skill and creates a path for accidental or unauthorized modification of campaign/task state.
The setup section instructs users to export sensitive API tokens but provides no warning about secret handling, shell history, logging, or avoiding disclosure back to the model. While common in CLI docs, this still increases the chance of credential exposure in shared terminals, transcripts, or support logs.
No suspicious patterns detected.