Back to skill

Security audit

t

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent with its purpose, but it should be reviewed because it encourages unpinned third-party skill installation globally while skipping confirmation.

Install only if you are comfortable letting this skill search for and add third-party agent skills. Before running its commands, verify the skill source and publisher, prefer pinned CLI versions and immutable skill references, avoid '-g' unless global install is necessary, and do not use '-y' unless you have already reviewed the exact package and destination.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
Skill.md:90
Finding

Unverified Third-Party Skill Installation with Global and Non-Interactive Flags

Content
View full analysis

Vulnerability Details

File Location: Skill.md, lines 90-95
Vulnerability Type: Supply-chain exposure through unpinned and unverified third-party installation
Risk Level: Medium

Vulnerable code snippet:

markdown
If the user wants to proceed, you can install the skill for them:

```bash
npx skills add <owner/repo@skill> -g -y

The -g flag installs globally (user-level) and -y skips confirmation prompts.

text

### Technical Analysis

The skill directs the agent to invoke an unpinned `npx skills` package and install third-party content identified by an externally supplied repository and skill name. The broader instructions explicitly state that skills can come from GitHub or other sources, but do not require source validation, version or commit pinning, integrity verification, content inspection, or an allowlist.

Using `npx` without a pinned package version can retrieve the current package release at execution time. The effective CLI implementation may therefore differ from the version that was previously reviewed. Likewise, the referenced skill can change if it is resolved through a mutable branch or tag.

The `-g` option expands the installation scope to the user's global skill environment, while `-y` suppresses confirmation prompts that could otherwise provide an opportunity to review the source and destination. These behaviors create a supply-chain risk if a package, repository, maintainer account, search result, or dependency is compromised or impersonated.

### Attack Path

1. An attacker publishes or compromises a skill repository, package, or dependency accepted by the Skills CLI.
2. The malicious skill appears in search results or is supplied to the agent as an installation candidate.
3. The user agrees to installation without receiving immutable source, integrity, or provenance information.
4. The agent executes `npx skills add <owner/repo@skill> -g -y`.
5. `npx` retrie
...[truncated 824 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the Skills CLI to a reviewed version, such as skills@<exact-version>, instead of resolving the latest mutable release.
  2. Pin installed skills to immutable commit hashes or cryptographically verified releases.
  3. Restrict installations to an explicit allowlist of trusted owners, repositories, and registries.
  4. Verify package provenance, signatures, checksums, ownership, and repository history before installation.
  5. Inspect downloaded skill instructions and scripts before loading or executing them.
  6. Remove -y so that installation requires an explicit confirmation after presenting the exact source, revision, requested scope, and security implications.
  7. Avoid -g by default. Prefer an isolated, project-local, sandboxed installation with minimal filesystem and network permissions.
  8. Run installation in a restricted environment that does not expose unrelated credentials or sensitive files.
  9. Document a rollback procedure and maintain an inventory of installed skill versions and source revisions.

T09 · Insecure Skill Coding Practices

Warning
Location
Skill.md:47
Finding

Unsafe Shell Construction Guidance for User-Derived Search Queries

Content
View full analysis

Vulnerability Details

File Location: Skill.md, lines 47-56
Vulnerability Type: Potential shell command injection through unquoted query substitution
Risk Level: Medium

Vulnerable code snippet:

markdown
Run the find command with a relevant query:

```bash
npx skills find [query]

For example:

  • User asks "how do I make my React app faster?" → npx skills find react performance
  • User asks "can you help me with PR reviews?" → npx skills find pr review
  • User asks "I need to create a changelog" → npx skills find changelog
text

### Technical Analysis

The skill instructs the agent to derive a search query from user input and place it into a shell command represented as `npx skills find [query]`. It provides no requirement to validate the query, quote it safely, reject shell metacharacters, or invoke the process through a structured argument array.

If an implementation replaces `[query]` with raw user-controlled text and passes the resulting string to a shell, characters such as command separators, substitutions, redirections, or pipelines may be interpreted by the shell rather than treated as search terms. The examples are benign, but the generic instruction does not establish a safe boundary between data and executable syntax.

Exploitation is contingent on the agent or runtime constructing a shell command string from the query. An implementation that invokes the executable directly with a structured argument array would not be vulnerable to shell metacharacter injection.

### Attack Path

1. An attacker asks the agent to find a skill using a query containing shell syntax.
2. The agent extracts the attacker-controlled text as the search query.
3. Following the documented pattern, the agent concatenates the raw query into `npx skills find [query]`.
4. The resulting command string is submitted to a shell.
5. The shell interprets attacker-controlled metacharacters and executes an addi
...[truncated 628 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not construct a shell command by concatenating the user-derived query.
  2. Invoke the CLI directly with a structured argument array, keeping each search term as data rather than shell syntax.
  3. Pin the invoked CLI to a reviewed exact version.
  4. If a shell is unavoidable, apply platform-appropriate escaping to every user-controlled argument and place arguments after an end-of-options marker where supported.
  5. Validate query length and character set, and reject control characters, newlines, shell operators, redirections, and command-substitution syntax.
  6. Update the documentation to state explicitly that user input must never be interpolated into a shell command.
  7. Prefer a pattern equivalent to the following structured invocation:
text
executable: npx
arguments: ["--yes", "skills@<pinned-version>", "find", "--", "<query>"]

The runtime must pass these as separate process arguments rather than joining them into a shell-evaluated string.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation criteria are very broad, including generic requests like 'how do I do X' or 'can you do X', which can trigger this skill in many situations where the user did not ask to install or search for external capabilities. In a skill that recommends package discovery and installation, overbroad invocation increases the chance of unsolicited exposure to risky commands and third-party content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a specific package version or integrity, which causes execution of whatever version is current at runtime. In a skill whose purpose is discovering and installing additional packages, this expands the trust boundary significantly and creates supply-chain risk if the package is updated maliciously or compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command reference uses unpinned npx skills, meaning users may execute an unexpected package version fetched at invocation time. Because this skill normalizes package installation from external sources, the lack of version pinning materially increases supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx skills add <package> without pinning the CLI version allows remote code execution through the latest published package version rather than a reviewed one. In this context, the CLI is also used to install further content from GitHub or other sources, compounding supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

npx skills check executes an unpinned package version, which still exposes users to package takeover or malicious updates even though the command itself is lower impact than installation. The surrounding skill teaches users to trust the CLI broadly, making accidental execution more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

npx skills update with an unpinned CLI introduces risk from both the CLI package and the update operation it performs. This is especially dangerous because it may change many installed skills at once based on current remote state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The search command npx skills find [query] still relies on unpinned runtime package execution. Although search is less privileged than installation, it conditions users to execute a remotely resolved package with no version control.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This example invocation uses npx skills without version pinning, exposing users to package substitution or malicious updates. The example is likely to be copied verbatim, increasing practical exploitability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The unpinned npx skills example for PR review searches executes an implicitly trusted latest package version. The risk is not the query but the package resolution and execution behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This example again uses an unpinned remote CLI package. Repetition throughout the skill reinforces unsafe operational patterns and increases the likelihood that users execute unreviewed package code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The installation instruction npx skills add <owner/repo@skill> compounds two trust issues: an unpinned CLI package and installation of externally sourced skills. In a skill specifically designed to bring in third-party capabilities, this materially enlarges the attack surface.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install example again uses unpinned npx skills, making the exact code executed dependent on current registry state. Because users are instructed to install external skill packages, compromise of the CLI or dependency chain could lead to arbitrary code execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill recommends -g -y global installation with confirmation bypass but does not pair it with a strong warning about system-wide changes, trust implications, or the need for explicit consent. This is dangerous because it normalizes silent, potentially privileged modifications from third-party sources in a package-installation workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

npx skills add <owner/repo@skill> -g -y is especially risky because it combines unpinned package execution with global installation and confirmation bypass. This can make system-wide changes non-interactively, so any compromise or mistake has broader and more immediate impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The suggestion to create a new skill with npx skills init still executes an unpinned package version. Even initialization commands can run arbitrary install-time or setup code from the resolved package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This repeated npx skills init guidance has the same unpinned execution risk and is likely to be copied directly by users. The broader skill context encourages expanding capabilities through third-party code, increasing the significance of supply-chain weaknesses.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.