Back to skill

Security audit

wand-skill222

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for using Wand UI in Vue 2 mobile projects, with no hidden execution behavior found.

Install this skill if you want Chinese-language Wand UI/Vue 2 component help. When following its setup examples, pin reviewed npm package versions and use a lockfile, and treat file-upload examples as needing normal user consent and privacy review in your app.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
SKILL.md:25
Finding

Unpinned Third-Party npm Dependencies Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:25
  • references/quickstart.md:6-8
  • references/quickstart.md:44

Vulnerability Type: Third-party dependencies are installed without exact version or integrity constraints
Risk Level: Low

Affected code in SKILL.md:25:

bash
npm install @weiyi/wand-ui

Affected code in references/quickstart.md:6-8:

bash
npm install @weiyi/wand-ui
# or
yarn add @weiyi/wand-ui

Affected code in references/quickstart.md:44:

bash
npm install babel-plugin-component -D

Technical Analysis

These installation commands do not specify reviewed dependency versions or integrity hashes. Consequently, npm or Yarn resolves a mutable package version from the configured registry at installation time. The installed code can therefore differ from the version that existed when the Skill was audited.

Package installation may execute dependency lifecycle scripts, including preinstall, install, and postinstall. If the named package, one of its transitive dependencies, or the configured package registry is compromised, malicious code could execute during installation. Even without malicious activity, an incompatible future release could introduce security regressions into generated projects.

The audit did not identify evidence that the named packages are currently malicious. The issue is the absence of controls that make dependency resolution reproducible and restrict exposure to future supply-chain compromise.

Attack Path

  1. An attacker compromises a referenced package, a transitive dependency, a maintainer account, or the package registry used by the developer.
  2. The attacker publishes a malicious version containing a lifecycle script or malicious runtime code.
  3. A developer follows the Skill documentation and runs an unpinned npm install or yarn add command.
  4. The package manager resolves the attacker-controlled r ...[truncated 1022 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace unconstrained installation examples with exact, reviewed versions, for example:
    bash
    npm install --save-exact @weiyi/wand-ui@<reviewed-version>
    npm install --save-dev --save-exact babel-plugin-component@<reviewed-version>
    
  2. Generate and commit package-lock.json or the applicable Yarn lockfile so transitive dependencies and integrity hashes are reproducible.
  3. In automated environments, use npm ci against the committed lockfile rather than dynamically resolving dependencies.
  4. Review package provenance, maintainers, release history, and registry source before selecting the pinned versions.
  5. Configure an approved registry and lock down package-manager configuration to reduce dependency-confusion and registry-substitution risks.
  6. Where package behavior permits, install with lifecycle scripts disabled, such as npm ci --ignore-scripts, and explicitly run only reviewed build steps afterward.
  7. Add dependency vulnerability and integrity scanning to CI, and update pinned versions through a controlled review process.
  8. Document the exact versions that were tested with this Skill and update them only after source and release verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill purpose and usage context only in that language. This creates a language/locale constraint without offering the user a choice or documenting that the skill is intentionally region-specific, which matches the policy-violation criteria for forced language behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The automatic trigger list includes broad, generic phrases such as requests for a 'mobile list' that are not uniquely tied to Wand UI. In an agent skill system, overly broad triggers can cause the skill to activate in unrelated contexts, injecting framework-specific guidance where it was not requested and potentially steering code generation or recommendations incorrectly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

该 Markdown 文档介绍了 Uploader 文件上传 组件的用法和事件,但没有提醒其会处理并传输用户选择的文件,可能涉及个人数据或敏感内容。对于会影响用户数据与隐私的能力,文档应提供明确的用户提示或注意事项。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructions, headings, and examples exclusively in Chinese, which can amount to a language/locale policy issue when no user opt-in or alternative language is offered. The content does not indicate that the guide is intentionally limited to a Chinese-speaking audience or region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The phrase "所有文档均为中文" indicates a fixed language constraint. Because the file does not mention user opt-in, multilingual support, or a justified region-specific limitation, this may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.