Back to skill

Security audit

bun-do

Security checks for vulnerabilities and agentic risk

Overview

This local task-management skill is not malicious, but it needs review because it can automatically modify or delete persistent task, project, and payment-tracking data with broad triggers.

Review before installing if you rely on this task store for important personal, project, or bill-tracking records. Prefer a pinned/local install, avoid elevated privileges, and require explicit confirmation before deletes, clear-done, mark-done, or autonomous progress logging.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Global Installation of a Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:22
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

markdown
**Start**: `bun-do start` (install: `bun install -g bun-do`)

Technical Analysis

The Skill instructs users or agents to install the bun-do package globally from a package registry without pinning a reviewed version or specifying an integrity hash, trusted registry, or verified publisher. Consequently, the installed artifact can change after the Skill has been audited.

Global package installation may also invoke package-controlled installation or lifecycle behavior under the privileges of the user running the command. This is unnecessary for merely communicating with the documented local REST API and increases the supply-chain attack surface.

This finding does not demonstrate that the current bun-do package is malicious. The risk arises because a registry compromise, package-owner compromise, dependency confusion event, or malicious future release could make the documented installation command retrieve unsafe code.

Attack Path

  1. An attacker compromises the package publisher or registry account, takes control of the package name, or causes an unsafe release to be selected.
  2. The attacker publishes a malicious version of bun-do or one of its transitive dependencies.
  3. A user or agent follows the Skill documentation and runs bun install -g bun-do.
  4. The package manager retrieves the currently selected unpinned release.
  5. Malicious package behavior executes during installation or when the globally installed bun-do command is subsequently invoked.
  6. The payload operates with the permissions of the installing user and may affect files, processes, credentials, or network resources accessible to that account.

Impact Assessment

Successful exploitation could result in arbitrary code execution with the privileges of the user perfo ...[truncated 437 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed release, for example:
    bash
    bun install -g bun-do@<reviewed-version>
    
  2. Document the authoritative package registry, source repository, package publisher, and expected integrity information.
  3. Verify the package artifact and its transitive dependencies before recommending installation.
  4. Prefer a lockfile-backed, project-local installation over a global installation where feasible.
  5. Run the service under a dedicated, unprivileged account or constrained environment with access only to its required data directory and loopback port.
  6. Avoid running the installation command with elevated privileges.
  7. Consider documenting an API-only workflow for users who already have a trusted service instance, because the Skill's task-management operations require access to the local API but do not inherently require globally installing a package.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough to match common conversational language like 'task', 'deadline', 'payment', or 'remind me', which can cause the skill to activate in situations where the user did not intend task modification. Because this skill supports create, edit, and delete actions, over-triggering can lead to unintended state changes and silent corruption or loss of local task/project data.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Add a task

bash
curl -s -X POST http://localhost:8000/api/tasks \
  -H 'Content-Type: application/json' \
  -d '{"title": "Buy milk", "date": "2026-03-01", "priority": "P2"}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The autonomous-use condition ('when an agent finishes work and needs to record progress') is underspecified and allows an agent to decide on its own when to write project/task data. That ambiguity increases the chance of unauthorized or incorrect entries being created without an explicit user request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exposes delete operations for tasks, subtasks, projects, and log entries without warning about irreversibility or requiring confirmation. In a natural-language workflow, this raises the risk of accidental destructive actions from ambiguous phrasing or misresolved IDs/titles.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Add a task

bash
curl -s -X POST http://localhost:8000/api/tasks \
  -H 'Content-Type: application/json' \
  -d '{"title": "Buy milk", "date": "2026-03-01", "priority": "P2"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

Edit (only send fields to change)

bash
curl -s -X PUT http://localhost:8000/api/tasks/TASK_ID \
  -H 'Content-Type: application/json' \
  -d '{"priority": "P0", "date": "2026-03-15"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The proactive patterns include autonomous modifications such as marking tasks done and adding project entries, but the skill does not clearly disclose that it may change stored data on its own. This can cause unexpected writes and inaccurate records, especially when completion status is inferred incorrectly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.