Back to skill

Security audit

Find Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to find and install other skills, but it recommends broad, global, confirmation-skipping installs from mutable third-party sources.

Review this carefully before installing. Use it only if you want an agent to search for and install skills, avoid global or confirmation-skipping installs by default, verify the exact source and revision of any skill, and prefer pinned or sandboxed tooling where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:27
Finding

Unpinned Third-Party CLI Execution and Unattended Global Skill Installation

Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` From `SKILL.md:50-58`: ```markdown ### Step 2: Search for Skills Run the find command with a relevant query: ```bash npx skills find [query] ``` ``` From `SKILL.md:86-90`: ```markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` ``` ### Technical Analysis The documented workflow invokes the `skills` package through `npx` without specifying an exact package version or verifying package integrity. Depending on the local package-manager state, `npx` may retrieve and execute the current package release from a remote registry. The security behavior of the command can therefore change after this skill has been reviewed. The workflow also permits installing skills from GitHub or unspecified “other sources.” No publisher allowlist, repository verification, immutable commit pin, signature check, checksum validation, source-code inspection, or permission review is required before installation. The installation command compounds this supply-chain exposure through the following options: - `-g` installs the downloaded skill globally at the user level, expanding its scope beyond the current project. - `-y` suppresses confirmation prompts that could otherwise provide an opportunity to inspect or reject the package. - `` may identify externally controlled content whose repository or branch can change after review. A malicious or compromis ...[truncated 2082 chars]
Remediation
View remediation
`. - Do not use floating tags such as `latest`. - Record and review version updates explicitly. 2. **Verify package provenance and integrity** - Use package-manager lockfiles and integrity hashes where supported. - Verify registry ownership, package signatures, release provenance, and repository identity. - Consider installing the reviewed CLI as a locked project dependency instead of downloading it dynamically for each invocation. 3. **Restrict acceptable skill sources** - Maintain an allowlist of trusted publishers and repositories. - Reject ambiguous package names, URL redirects, forks, and unapproved “other sources.” - Pin GitHub installations to immutable, reviewed commit hashes rather than mutable branches or tags. 4. **Inspect content before activation** - Download skills into an isolated staging directory first. - Review manifests, instruction files, scripts, hooks, dependencies, and requested permissions. - Scan downloaded content for remote execution, credential access, persistence, destructive commands, and instruction hijacking. 5. **Avoid unattended global installation** - Remove `-g` and install into a project-scoped or sandboxed directory by default. - Remove `-y` so the exact source and changes are presented before installation. - Require explicit informed user approval after displaying the publisher, repository URL, immutable revision, affected paths, and requested permissions. 6. **Apply execution isolation** - Run discovery and installation with minimal filesystem and network permissions. - Prevent access to credentials and sensitive environment variables during package execution. - Test newly installed skills in an isolated environment before making them available to normal agent sessions. 7. **Secur ...[truncated 213 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The metadata description makes the skill trigger on broad requests like 'how do I do X' or general interest in extending capabilities, which overlaps with many ordinary help interactions. Over-broad routing can cause the agent to invoke package discovery and installation guidance in situations where the user only wanted advice, increasing the chance of unnecessary exposure to external code and package-manager actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs that if the user wants to proceed, the agent can run npx skills add <owner/repo@skill> -g -y, which performs global installation of third-party code while bypassing confirmation prompts. This is highly dangerous because it combines remote code acquisition, broad system/user-level persistence, and removal of an interactive safety check, making accidental or malicious installation far more likely and impactful.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage section lists many ambiguous triggers like 'can you do X' and 'expresses interest in extending agent capabilities' without clear boundaries. That ambiguity can lead to inappropriate invocation of a skill that promotes third-party package discovery, which expands the attack surface through needless external recommendations or installs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning an exact package version, which means execution will resolve whatever version is current at runtime. Because this skill is specifically about discovering and installing more code from external sources, an upstream package compromise, typo-squatting, or breaking update could immediately lead to arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx skills without a pinned version causes the package manager to fetch and execute mutable remote code. In a skill whose purpose is package discovery and installation, that creates a strong supply-chain risk because the very first step relies on trust in an unversioned external package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The command example executes an unpinned npx package, allowing behavior to change over time or be hijacked through package compromise. Since users may copy-paste these commands directly, this creates a realistic path to unintended code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

An unpinned npx skills invocation delegates execution to a mutable upstream package, which is a classic supply-chain exposure. The surrounding skill context increases risk because it normalizes executing package-manager commands from discovered third-party sources.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The update command again relies on unpinned remote code, meaning a future upstream release could alter behavior or introduce malicious logic. Update workflows are especially sensitive because they may affect all installed skills at once.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The search step tells the agent to run npx skills find [query] without pinning the package version, exposing users to supply-chain risk before any results are even evaluated. This is dangerous because it makes untrusted remote code execution part of normal discovery behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This example search command uses an unpinned remote package, so copy-paste usage can execute unexpected code if the package changes or is compromised. The risk is amplified because the command is presented as a routine first step for users seeking help.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The PR review example still depends on mutable npx package resolution, enabling arbitrary code execution through upstream compromise. Repetition throughout the skill reinforces insecure operational habits.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This command demonstrates unpinned execution of an external CLI in a context where users are encouraged to search and install more code. That combination creates a layered supply-chain risk: first the CLI, then the discovered package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The installation snippet tells users to run npx skills add <owner/repo@skill> without pinning the CLI version, again relying on mutable remote code. Although the main danger is the same supply-chain issue, this line also normalizes installation of third-party code without emphasizing verification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The example install command uses an unpinned npx package, leaving execution dependent on whatever version is served at that time. In a package-install context, even benign drift can have significant consequences for security and reproducibility.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This line instructs installation via npx skills add ... -g -y but still leaves the CLI itself unpinned, so both the installer and the installed artifact sit behind mutable trust boundaries. Because it performs a global install with confirmation bypass, any compromise in the CLI or process could immediately alter the user's environment broadly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Even the fallback guidance to run npx skills init uses an unpinned package, exposing users to the same upstream execution risk. While less severe than global install guidance, it still encourages trust in mutable remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This reference again promotes unpinned npx skills, reinforcing an insecure pattern across the document. Repetition matters here because widespread examples increase the chance users will adopt unsafe commands without scrutiny.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.