Back to skill

Security audit

technical writing

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent documentation helper, but it includes copy-ready unsafe command examples that could run remote code or disrupt services if reused without review.

Install only if you are comfortable reviewing generated documentation before publishing or running any commands from it. Replace the remote installer pipeline with verified package or checksum-based install steps, and add explicit approval, environment confirmation, impact, rollback, and post-check guidance around runbook commands before using the templates operationally.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:171
Finding

Unverified Remote Script Executed Through a Shell Pipeline

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 171
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://get.my-cli.dev | sh

Technical Analysis

The CLI README template retrieves a shell script from an external domain and pipes the response directly into sh. The command does not pin an immutable release, verify a cryptographic checksum or signature, save the script for inspection, or establish that the placeholder domain is a trusted distribution source.

Consequently, the effective code is not contained in the reviewed Skill and can change at any time. Compromise, reassignment, or malicious control of the domain, its hosting infrastructure, DNS resolution, or release process would allow arbitrary shell commands to be returned and executed.

The command appears in documentation rather than an automatically invoked script. Nevertheless, it is a copy-ready installation instruction in a Skill intended to produce reusable developer documentation. An agent may reproduce it in generated documentation, after which a user may execute it as an installation command. Remote code execution is unnecessary for the Skill's declared technical-writing functionality and exceeds the minimum privileges needed to provide a documentation template.

Attack Path

  1. An agent uses or reproduces the CLI README template from SKILL.md.
  2. The generated documentation retains the curl | sh installation command.
  3. An attacker controls or compromises get.my-cli.dev, its hosting environment, DNS path, or publication process.
  4. A user follows the generated installation instructions.
  5. curl downloads the attacker-controlled response.
  6. The shell immediately executes that response without integrity verification or prior inspection.
  7. The payload performs arbitrary actions using the invoking user's permissions.

Impact Assessment

Successful exploitation provides arbitra ...[truncated 693 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh pipeline from the template.
  2. Prefer an established package manager or verified official release channel.
  3. If a script-based installer is required:
    • Pin an immutable version.
    • Download the installer to a local file.
    • Publish and verify a cryptographic checksum or signature through an independent trusted channel.
    • Display or inspect the downloaded script before execution.
    • Require explicit user confirmation before running it.
    • Run it without elevated privileges unless a documented operation strictly requires elevation.
  4. Replace the placeholder domain with a clearly non-executable example, or label the command explicitly as unsafe pseudocode that must not be copied.
  5. Add documentation security guidance prohibiting remote responses from being piped directly into a shell.

A safer illustrative pattern is:

bash
version="1.2.3"
curl -fL -o install.sh \
  "https://downloads.example.invalid/my-cli/${version}/install.sh"

echo "EXPECTED_SHA256  install.sh" | sha256sum --check -
less install.sh
sh install.sh

The checksum must be obtained from a trusted, independently authenticated release source. The .invalid domain above is intentionally non-routable and should be replaced only with a verified official source.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (32)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching a remote script with curl and immediately executing it is a classic high-risk pattern because it grants full shell execution to content retrieved over the network at runtime. Within a documentation skill that aims to provide reusable templates, including this pattern normalizes unsafe operational behavior and materially increases the chance of arbitrary code execution on user systems.

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

brew install my-cli

Binary

curl -fsSL https://get.my-cli.dev | sh

text

## Quick Start

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh chain turns downloaded network content directly into code execution, removing any opportunity for inspection and greatly amplifying the danger of a compromised endpoint, DNS hijack, or supply-chain attack. Because the skill is instructional and likely to be copy-pasted, the chaining pattern is especially hazardous in context.

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

brew install my-cli

Binary

curl -fsSL https://get.my-cli.dev | sh

text

## Quick Start

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 308)May include surrounding context.

bash
git clone https://github.com/org/my-api.git
cd my-api
cp .env.example .env
docker compose up -d
npm run dev

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 422)May include surrounding context.

md
Accepted (2025-01-15)

<!-- Proposed | Accepted | Deprecated | Superseded by ADR-XXX -->

## Context

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/runbook-template.md (reported line 12)May include surrounding context.

md
## Symptoms

<!-- How do you know this issue is happening? List observable symptoms. -->

- [ ] Alert: [Alert name and link to monitoring dashboard]
- [ ] Error in logs: `[exact error message or pattern]`

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to activate the skill whenever a user asks to write, structure, or improve developer documentation, which is a very broad invocation condition rather than a narrow trigger. It does not provide explicit trigger phrases, exclusions, or negative examples, so the skill may be invoked for many ordinary documentation requests without clear boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI installation example includes curl -fsSL https://get.my-cli.dev | sh, which executes remote code directly in a shell without inspection, integrity verification, or provenance checks. In a skill that provides copy-paste-ready documentation templates, this is especially dangerous because users may reproduce the pattern verbatim and run attacker-controlled or compromised installer content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

All requests require a Bearer token:

bash
curl -H "Authorization: Bearer YOUR_TOKEN" https://api.example.com/v1/widgets

Quick Start

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The runbook instructs terminating database sessions and restarting an application as immediate remediation, but it does not warn about potential service interruption, transaction loss, or coordination requirements. In an operational runbook, terse high-impact commands can be executed under pressure, increasing the chance of avoidable outage amplification.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

Including sudo systemctl restart my-app in a generic runbook encourages privileged command execution without documenting authorization, environment constraints, or service-impact checks. In high-stress incident response, privileged commands shown without safety framing can lead to misuse or unnecessary disruption.

Content

Scanner excerpt · SKILL.md (reported line 740)May include surrounding context.

AND now() - state_change > interval '5 minutes';"

Restart application to reset connection pool

sudo systemctl restart my-app

text

### Short-term (prevent recurrence)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This runbook template includes operational commands that can change production state, such as restarting services, scaling deployments, enabling maintenance mode, and rolling back releases, but it does not include explicit preconditions, approval requirements, environment validation, or confirmation guidance before execution. In a documentation skill, users may copy and run these commands directly, which increases the risk of accidental service disruption or unintended changes in the wrong environment.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The template includes a privileged command, 'sudo systemctl restart my-service', which can directly alter production service state. In the context of a reusable runbook template, presenting root-level commands without guardrails can lead to accidental misuse, especially if copied by less experienced responders or adapted without access-control and change-management notes.

Content

Scanner excerpt · examples/runbook-template.md (reported line 87)May include surrounding context.

bash
# Option A: Restart the service
sudo systemctl restart my-service

# Option B: Scale up (if capacity issue)
kubectl scale deployment my-app --replicas=5

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 248)May include surrounding context.

Diagnosis

bash
# Step 1: Check service health
curl -s https://api.example.com/health

Remediation

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

Diagnosis

bash
# Step 1: Check service health
curl -s https://api.example.com/health

Remediation

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

Diagnosis

bash
# Step 1: Check service health
curl -s https://api.example.com/health

Remediation

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

Diagnosis

bash
# Step 1: Check service health
curl -s https://api.example.com/health

Remediation

Static analysis

No suspicious patterns detected.