Back to skill

Security audit

Open Code Review

Security checks for vulnerabilities and agentic risk

Overview

The skill’s code-review purpose is coherent, but its setup examples rely on mutable, unpinned third-party execution in developer, CI, and MCP environments.

Install only after pinning the npm CLI and MCP server to reviewed versions, prefer lockfile-backed installs for CI, pin the GitHub Action to a commit SHA, and run scans with minimal repository, token, secret, and network permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:26
Finding

Unpinned npm CLI Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26–35
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

bash
# Install
npx @opencodereview/cli scan ./src --sla L1

# With AI-powered deep scan (requires Ollama or API key)
npx @opencodereview/cli scan ./src --sla L2

# Diff mode for CI/CD
npx @opencodereview/cli scan ./src --diff --base origin/main --head HEAD

# SARIF output for GitHub Actions
npx @opencodereview/cli scan ./src --format sarif --output results.sarif

Technical Analysis

The documented commands execute @opencodereview/cli through npx without specifying an exact package version or verifying package integrity. If the package is not already available locally, npx can retrieve executable code from the npm registry at invocation time.

Consequently, the code executed by these commands may differ from the code that existed when this Skill was reviewed. A compromised npm publisher account, malicious package release, registry compromise, or unauthorized ownership transfer could turn the documented command into a supply-chain execution vector.

The project contains no evidence that the current package is malicious. The vulnerability is the absence of version pinning and integrity controls around third-party executable retrieval.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or another relevant distribution component.
  2. The attacker publishes a malicious version of @opencodereview/cli.
  3. A developer or automation system follows the documented unversioned npx command.
  4. npx resolves and downloads the attacker-controlled package version.
  5. Package lifecycle behavior or the invoked CLI executes with the permissions of the developer or automation account.
  6. The malicious dependency accesses repository contents, environment variables, credentials, or other resources available to that ...[truncated 532 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the CLI to an exact, reviewed version, such as @opencodereview/cli@X.Y.Z.
  • Install dependencies through a committed lockfile using a deterministic installation command such as npm ci.
  • Verify package integrity and provenance before approving version updates.
  • Disable or restrict unnecessary package lifecycle scripts where operationally feasible.
  • Run the scanner in a sandbox or isolated CI job with read-only repository access, minimal credentials, and restricted network access.
  • Use controlled dependency-update tooling so that version changes receive explicit review and security testing.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

GitHub Action Referenced Through a Mutable Version Tag

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–51
Vulnerability Type: Mutable third-party CI dependency
Risk Level: Medium

yaml
- uses: raye-deng/open-code-review@v1
  with:
    scan-path: src/
    sla-level: L1
    diff-mode: true

Technical Analysis

The GitHub Action is referenced using the mutable v1 tag rather than a full immutable commit SHA. Repository maintainers—or an attacker who compromises the repository or its release credentials—can move this tag to different code after the Skill and consuming workflow have been reviewed.

GitHub Actions execute code inside CI runners and commonly receive access to checked-out source code, workflow tokens, environment variables, caches, and configured secrets. A mutable reference therefore weakens reproducibility and allows the effective dependency payload to change without a corresponding modification to the consuming workflow.

There is no evidence in the audited file that the referenced Action is currently malicious. The risk arises from trusting a mutable supply-chain reference.

Attack Path

  1. An attacker compromises the Action repository, a maintainer account, or its release process.
  2. The attacker modifies or moves the v1 tag so that it resolves to malicious Action code.
  3. A repository using the documented configuration triggers the affected workflow.
  4. GitHub resolves raye-deng/open-code-review@v1 to the attacker-controlled revision.
  5. The malicious Action executes on the CI runner.
  6. It reads or alters resources available to the job and may exfiltrate source code, tokens, or secrets if runner permissions permit.

Impact Assessment

Exploitation could provide arbitrary execution within the CI runner's security context. Potentially exposed resources include repository source, generated artifacts, caches, workflow tokens, and secrets explicitly made available to the job.

If the workflow grants write perm ...[truncated 237 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable tag with a full reviewed commit SHA.
  • Retain a version comment beside the SHA for maintainability, while ensuring the executable reference remains immutable.
  • Configure minimal GitHub Actions permissions, defaulting the workflow token to read-only.
  • Do not expose secrets to the scanning job unless strictly required.
  • Use dependency-management tooling to propose and review Action SHA updates.
  • Run third-party Actions in isolated jobs and restrict network access or runner privileges where supported.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:72
Finding

Unattended Execution of an Unpinned npm MCP Server

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 72–74
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

json
"command": "npx",
"args": ["-y", "@opencodereview/mcp-server"]

Technical Analysis

This MCP configuration invokes npx with the -y option and does not pin @opencodereview/mcp-server to an exact version. The configuration can therefore download and execute a future npm release without interactive confirmation.

Because an MCP server is a persistent tool process for the duration of its host session, compromised server code may be able to process tool requests and access any files, environment variables, credentials, or network resources exposed by the MCP host. The absence of a version pin also means the effective executable can change after review.

No evidence establishes that the current MCP package is malicious. The confirmed weakness is the unattended retrieval and execution of an unpinned third-party executable.

Attack Path

  1. An attacker compromises the npm package publisher, release pipeline, or distribution channel.
  2. The attacker publishes a malicious version of @opencodereview/mcp-server.
  3. A user adds the documented configuration to an MCP-compatible client.
  4. The client invokes npx -y, which resolves and downloads the malicious version without requesting confirmation.
  5. The package executes with the MCP host user's privileges.
  6. The malicious process accesses or exfiltrates resources available to the host, subject to its sandbox and permission boundaries.

Impact Assessment

Successful exploitation could yield arbitrary code execution under the MCP client's operating-system account. Potentially exposed assets include repositories, user files, environment variables, API credentials, and network-accessible services available to that process.

The -y option removes an interactive checkpoint but does not itself elev ...[truncated 144 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin @opencodereview/mcp-server to an exact reviewed version.
  • Prefer a locally installed dependency managed through a committed lockfile instead of downloading it on every launch.
  • Verify package integrity and provenance as part of installation and updates.
  • Avoid npx -y for first-time or unreviewed package execution.
  • Run the MCP server in a sandbox with narrowly scoped filesystem access, filtered environment variables, no unnecessary credentials, and restricted network access.
  • Require explicit review and testing before updating the pinned server version.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation instructs users to execute an unpinned npm package via npx, which fetches the latest published version at runtime. If the package is compromised, a malicious version is published, or a breaking change lands, users and CI systems may execute unexpected code without review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This command also uses npx with no explicit version, so execution depends on whatever version is current in the registry at the time of use. That creates supply-chain and reproducibility risk, especially because the command is presented as part of a deeper AI-powered scan that users may run in automated environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

An unpinned npx invocation in diff-mode can be copied directly into CI pipelines, where a later package update could alter behavior or introduce malicious code. Because npx resolves from the registry by default, this increases supply-chain exposure beyond a local documentation issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The SARIF example likewise relies on an unpinned package fetched at execution time, which can lead to non-reproducible results and potential execution of compromised code. In a security-tooling context, this is more concerning because users may trust the tool in privileged developer or CI environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.