Back to skill

Security audit

x-hacker-news

Security checks for vulnerabilities and agentic risk

Overview

The skill is for Hacker News lookups, but it requires sourcing an unpinned external shell framework with the agent's privileges.

Review before installing. Use it only if you already trust the x-cmd installation source and are comfortable letting its shell initialization code run with the same filesystem, environment, and network access as your agent. Prefer running it in a constrained environment without unrelated credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned External Shell Framework Is Sourced with Agent Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24 and 38-45; supporting dependency references at lines 293-300
Vulnerability Type: Untrusted and unpinned external shell dependency
Risk Level: Medium

Vulnerable Code

markdown
**IMPORTANT**: Before using any `x hn` command, you MUST load x-cmd first: `. ~/.x-cmd.root/X`
markdown
## Loading x-cmd

**Not installed?** -> **Search and use the `x-cmd` skill to install x-cmd first**

**Installed?** -> Load x-cmd:

```bash
. ~/.x-cmd.root/X
text

Supporting dependency and remote-resource declarations:

```markdown
## Dependencies

- x-cmd (required): provides hn module
- x jq (optional): JSON processing via x-cmd

---

## More: https://x-cmd.com/llms.txt

Entrance for AI agents.

Technical Analysis

The Skill requires the Agent to execute the external initialization file ~/.x-cmd.root/X using the POSIX dot command. Unlike launching a separate executable, sourcing a file evaluates all of its commands directly in the current shell. The sourced code can therefore inspect inherited environment variables, alter shell functions and command resolution, change working state, and execute arbitrary commands with the same operating-system privileges as the Agent.

Neither the initialization file nor the implementation of x hn is included in the audited project. The installation is delegated to another Skill, while no immutable version, cryptographic checksum, signature, or reviewed distribution artifact is specified. Consequently, the dependency's effective behavior, update process, network destinations, and access to local data cannot be verified from this package.

The network activity required to retrieve public Hacker News content is consistent with the declared functionality. The documented command examples only supply public story identifiers, ranges, and Hacker News usernames; they do not explicitly transmit cr ...[truncated 1988 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin x-cmd to a specific reviewed release or immutable commit rather than directing the Agent to install an unspecified current version.
  2. Obtain the dependency only from a documented official source and verify a cryptographic signature or published checksum before execution.
  3. Replace . ~/.x-cmd.root/X with invocation of a narrowly scoped executable in a separate subprocess. Avoid sourcing third-party initialization code into the Agent's current shell.
  4. Run the dependency with a sanitized environment that excludes unrelated API keys, tokens, and credentials.
  5. Restrict filesystem access to only the directories required for Hacker News retrieval and caching, and restrict outbound traffic to documented Hacker News or approved service endpoints.
  6. Document the exact installation source, expected files, version, network endpoints, cache behavior, and update policy so the dependency can be independently audited.
  7. Disable automatic updates during Skill execution. Review and re-verify each dependency update before deployment.
  8. If shell initialization remains unavoidable, validate ownership and permissions of ~/.x-cmd.root/X, inspect its complete dependency chain, and execute it within a sandboxed process rather than a privileged or credential-rich Agent session.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.