Back to skill

Security audit

Find Skills (Robin's Fork)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent skill-finder, but it normalizes unpinned remote CLI execution and non-interactive global installation of third-party skills.

Review the source and version of any skill before installing it. Prefer pinned CLI and skill versions, avoid `-y` for installs, and use global installation only when you want the skill to persist across agent sessions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Third-Party CLI Execution and Non-Interactive Global Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24-30, 48-58, and 80-84
Vulnerability Type: Supply-chain exposure through unpinned packages and insufficiently verified skill sources
Risk Level: Medium

Vulnerable Code

SKILL.md, lines 24-30:

bash
npx skills find [query]
npx skills add <package>
npx skills check
npx skills update

SKILL.md, lines 48-58:

bash
npx skills find [query]

For example:

  • User asks "how do I make my React app faster?" → npx skills find react performance
  • User asks "can you help me with PR reviews?" → npx skills find pr review
  • User asks "I need to create a changelog" → npx skills find changelog

SKILL.md, lines 80-84:

bash
npx skills add <owner/repo@skill> -g -y

The -g flag installs globally (user-level) and -y skips confirmation prompts.

Technical Analysis

The skill directs the agent to execute npx skills without specifying an exact package version or validating package integrity. Depending on the local npm cache and registry resolution, npx can download and execute the currently resolved version of the package. Consequently, the effective executable is not immutable at the time this skill is reviewed.

The CLI is then used to discover and install skills from GitHub or other sources. The documented workflow does not require repository allowlisting, immutable commit pinning, signature verification, integrity verification, or inspection of the downloaded skill before installation. The recommended installation command also combines global installation (-g) with confirmation suppression (-y), reducing user visibility and extending the installed component's scope beyond the current project.

This is an insecure dependency and supply-chain pattern rather than evidence that the currently referenced CLI or repositories are malicious.

Attack Path

  1. An attacker compromises the npm packa ...[truncated 1466 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an audited, exact version, for example npx --package=skills-cli@X.Y.Z, using the correct verified package name and version for the ecosystem.
  2. Enforce package-lock integrity metadata or an equivalent cryptographic verification mechanism before execution.
  3. Restrict skill discovery and installation to an explicit allowlist of trusted organizations and repositories.
  4. Pin installed skills to immutable commit hashes rather than mutable branches, tags, or search-result identifiers.
  5. Download and inspect skill manifests, instructions, scripts, lifecycle hooks, and dependency declarations before installation or execution.
  6. Install skills locally and within a sandbox by default. Global installation should require a separate, informed user decision.
  7. Remove -y from the recommended command so that the package, source, version, requested scope, and intended changes can be reviewed before installation.
  8. Require explicit user approval before running updates because updates can replace previously reviewed content.
  9. Execute package installation with minimal privileges, restricted filesystem access, limited environment variables, and controlled network access.
  10. Record the verified source repository, immutable revision, hashes, and audit result for every installed skill.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The metadata description defines broad triggers like 'how do I do X' and 'can...' that overlap with ordinary user requests. In context, this is dangerous because it can cause the skill to activate in many benign conversations and steer the agent toward searching for and installing external skills unnecessarily, increasing exposure to untrusted code paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The 'When to Use This Skill' section uses ambiguous conditions like any specialized capability request or general interest in tools/workflows. Because this skill leads to external package discovery and possible installation, overbroad activation materially increases the chance of unnecessary invocation and accidental escalation into supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a specific package version. Because npx resolves and executes code from the registry at runtime, a compromised upstream package, dependency, or unexpected new release could cause arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command reference relies on unpinned npx skills, which downloads and runs the latest available package version. That creates a supply-chain execution path where users may unknowingly run malicious or incompatible code if the package or its dependencies are altered upstream.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill advertises npx skills add <package> without constraining the CLI version. An attacker who compromises the package or publishes a malicious release could exploit the trust in this documentation to execute arbitrary code during install or subsequent CLI actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx skills check without a pinned version still executes remote package code and therefore exposes users to upstream compromise. The immediate command appears read-only, but the security issue remains because the CLI itself must be fetched and run.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

npx skills update without version pinning compounds supply-chain risk because it both executes an unpinned CLI and updates additional external content. A malicious upstream release could abuse the update path to install or modify code broadly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The search instruction again normalizes execution of unpinned npx skills, which is a supply-chain risk. Repetition throughout the skill increases the chance that users or agents will treat this as the default safe workflow and run transient remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This example command uses unpinned npx skills find react performance, exposing the environment to arbitrary code execution from the latest published CLI package. Even example commands matter because users often copy-paste them directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This copy-pasteable example uses npx skills find pr review without a fixed version. That gives an attacker controlling the package distribution channel an opportunity to run code in the user's context under the guise of a harmless search operation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The example npx skills find changelog has the same unpinned runtime dependency risk as the other commands. Because it is framed as a routine discovery step, it may lower user caution around executing remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The installation snippet encourages npx skills add <owner/repo@skill> while leaving the CLI unpinned. This creates dual trust problems: unpinned execution of the installer itself and installation of external skill content from third-party repositories.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill explicitly says it can install a skill for the user using npx skills add <owner/repo@skill> -g -y, but still leaves the CLI unpinned. This is more dangerous in context because it encourages automated execution of remote code with global installation and no confirmation, increasing blast radius and reducing user review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation recommends -g -y installation, which globally installs third-party skill code while suppressing confirmation prompts, and it does so without any warning about source trust, code execution, or system impact. In this skill's context, that meaningfully increases the chance of silent installation of malicious or inappropriate code with broad persistence in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The concrete install example presents an unpinned npx skills add ... command that users are likely to copy. In context, this is particularly risky because it normalizes installing executable third-party skills from external sources via a transient unpinned CLI.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Suggesting npx skills init without pinning still executes a remote package, though the direct impact is somewhat lower than install/update flows. The core issue remains that package resolution is mutable and could be abused for code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This final reference again promotes npx skills without version pinning, reinforcing an unsafe operational pattern throughout the skill. Repeated unsafe examples increase the likelihood of widespread adoption and successful exploitation if the package supply chain is compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.