Back to skill

Security audit

dada

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned backend tooling, but it asks users to run a mutable unpinned external CLI that will control persistent data, webhooks, and local identity keys.

Install only if you trust the `@usedada/cli` publisher and are comfortable with the CLI managing hosted data, webhooks, and a local identity key. Prefer a pinned CLI version or verified release binary, use a separate project for testing, avoid broad update/delete filters, protect webhook URLs as secrets, and keep the local key material on a trusted machine.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned External CLI Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–17
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

markdown
npx (requires Node.js):
sh
npx @usedada/cli

Technical Analysis

The skill instructs users and agents to execute @usedada/cli through npx without specifying an exact package version. Depending on local npm behavior and cache state, npx can retrieve the current package release from the npm registry and execute it with the invoking user's permissions.

The audited project contains only SKILL.md and package.json; it does not contain the source code of @usedada/cli, a lockfile, an integrity hash, or another mechanism that binds this instruction to a reviewed artifact. The executable dependency is also distinct from the audited @usedada/plugin package. Consequently, the code that executes can change after this skill has been reviewed.

No evidence establishes that the current external package is malicious. The risk arises from the mutable and unaudited supply-chain execution path.

Attack Path

  1. An attacker compromises the npm package, its publisher account, a maintainer's credentials, or another part of the package publication process.
  2. The attacker publishes a malicious or backdoored release under the legitimate @usedada/cli package name.
  3. A user or agent follows the skill instruction and runs npx @usedada/cli.
  4. npx resolves and downloads the mutable package release.
  5. Package lifecycle scripts or CLI entry-point code execute locally with the permissions of the invoking account.
  6. The malicious code accesses or modifies resources available to that account before, during, or after presenting expected CLI behavior.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the invoking user's operating-system privileges. The accessible scope could include project files, user-readable files, envi ...[truncated 301 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the command to a reviewed, immutable version, for example:

    sh
    npx --yes @usedada/cli@x.y.z
    
  2. Review the source and publication provenance of that exact release before recommending it.

  3. Publish SHA-256 checksums and, preferably, cryptographic signatures or attestations for prebuilt binaries, together with verification commands.

  4. Link to an immutable source revision corresponding exactly to the pinned npm and binary releases.

  5. Use package-lock or equivalent integrity metadata where the CLI is installed as part of a managed project.

  6. Disable or avoid dependency lifecycle scripts where operationally practical.

  7. Run the CLI with least privilege and avoid elevated execution.

  8. Document where the Ed25519 private key is stored, its file permissions, backup expectations, and revocation or rotation procedures.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx @usedada/cli without pinning a specific version, which means the executed code can change over time and could be replaced by a compromised or malicious package release. Because this is an installation/execution path for agent infrastructure tooling, a supply-chain compromise could lead to arbitrary code execution on the host running the agent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This repeated reference again directs execution of an unpinned package via npx, creating the same supply-chain risk: the fetched code is not fixed to a reviewed version. In an agent skill, this is especially risky because the CLI may be invoked automatically or with elevated access to local files, credentials, or project data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation includes insert, update, delete, and bulk data modification commands without any warning about irreversible changes, confirmation patterns, backups, or safe-scoping practices. In an agent-facing skill for persistent storage, this raises the chance of accidental data loss, mass modification, or misuse through poorly constrained automated actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The webhook section describes creating public inbound endpoints and streaming/dequeuing event contents without warning that webhook URLs may expose data or be abused if leaked. Since this skill is for backend infrastructure, agents may create endpoints that receive sensitive payloads, making privacy, authentication, and event-handling guidance important.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The setup flow states that an Ed25519 keypair is created and stored locally but gives no warning about protecting the local credential material, filesystem permissions, backups, or multi-user environments. While not inherently malicious, this omission can lead to credential theft or unintended account reuse if the host is shared or compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.