Back to skill

Security audit

capgo-live-updates

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Capgo live-update guide with disclosed external service use and automation, but users should apply normal release-governance and supply-chain precautions.

Install this only if you are intentionally adding Capgo OTA updates to a Capacitor app. Before using the CI examples, pin CLI and container versions, protect CAPGO_TOKEN, test through beta or staged channels, keep release changelogs and approval controls, and confirm that your update practices comply with app-store and user-consent expectations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill promotes automatic live updates and explicitly highlights skipping app store review, but it does not clearly warn that user-facing behavior can change without explicit user consent or strong governance. In the context of OTA code delivery, this can enable unsafe rollout practices, policy violations, or trust-eroding changes that are harder for users and reviewers to detect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'When to Use This Skill' section includes broad triggers such as 'User wants live/OTA updates' and 'User needs to push hotfixes quickly,' which could match many general app-update conversations. The file does not provide negative examples or scope constraints to clarify when this Capgo-specific skill should not be invoked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
autoUpdate: true,
    // Update behavior
    resetWhenUpdate: true,           // Reset to built-in on native update
    updateUrl: 'https://api.capgo.app/updates', // Default
    statsUrl: 'https://api.capgo.app/stats',    // Analytics

    // Channels

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
autoUpdate: true,
    // Update behavior
    resetWhenUpdate: true,           // Reset to built-in on native update
    updateUrl: 'https://api.capgo.app/updates', // Default
    statsUrl: 'https://api.capgo.app/stats',    // Analytics

    // Channels

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx @capgo/cli bundle upload without a pinned version can fetch and execute the latest published package at runtime in CI. If the package is compromised, typo-squatted, or unexpectedly changed, the build pipeline could execute attacker-controlled code with access to repository contents and deployment secrets such as CAPGO_TOKEN.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This GitLab CI example also uses npx @capgo/cli bundle upload without version pinning, creating the same runtime package-fetch risk in an automated deployment environment. CI runners typically hold tokens and source code, so a malicious or altered upstream package could exfiltrate secrets or tamper with release artifacts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The self-hosting example runs capgo/capgo-server without a tag or digest, which pulls a mutable image reference. This can silently change over time or be replaced upstream, exposing deployers to supply-chain compromise and making builds non-reproducible.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad phrases such as 'live updates', 'ota updates', 'skip app store', and 'hotfix' that can match many generic software-deployment requests without clearly requiring Capgo-specific intent. This can cause the skill to activate in situations where users did not ask for this tool specifically, increasing the chance of inappropriate guidance around bypassing normal app-store distribution controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames this skill as a guide for implementing Capgo live updates in Capacitor apps, covering account setup, plugin installation, configuration, update strategies, and CI/CD. The self-hosted section goes beyond app integration and instructs users to run backend infrastructure with Docker and database configuration, which is a separate operational capability not clearly justified by the stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.