Back to skill

Security audit

find-slills

Security checks for vulnerabilities and agentic risk

Overview

The skill’s purpose is clear, but it recommends broad-triggered, unpinned remote installs of other skills, including global no-confirm installs.

Review installs manually before using this skill. Prefer pinned CLI versions, exact skill revisions, local or scoped installs, and visible confirmation that identifies the source and publisher. Avoid using the documented global no-confirm install path for untrusted skills.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party CLI Execution and Unattended Global Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 28–31 and 78–82
Vulnerability Type: Unreviewed third-party package execution and installation
Risk Level: Medium

Vulnerable Code

markdown
**Key commands:**

- `npx skills find [query]` - Search for skills interactively or by keyword
- `npx skills add <package>` - Install a skill from GitHub or other sources
markdown
If the user wants to proceed, you can install the skill for them:

```bash
npx skills add <owner/repo@skill> -g -y
text

### Technical Analysis

The documented workflow invokes the `skills` CLI through `npx` without pinning the CLI to a reviewed version or verifying its integrity. If the package is not already available locally, `npx` may download and execute package code obtained from an external package registry. The effective CLI implementation can therefore change after this skill has been reviewed.

The workflow also permits installation from GitHub or other third-party sources without requiring an allowlist, immutable commit reference, signature, checksum, provenance verification, or source review. The recommended `-g -y` flags install the selected skill globally at the user level and suppress interactive confirmation. This broadens the installation scope and removes an opportunity for the user to inspect or reject the operation.

This constitutes an insecure dependency and supply-chain pattern. A compromised CLI release, registry account, upstream repository, mutable branch, or misleading search result could cause attacker-controlled package content to be downloaded and installed.

### Attack Path

1. A user asks the agent to locate functionality available as an installable skill.
2. The agent follows `SKILL.md` and runs the unpinned `npx skills find [query]` command.
3. `npx` retrieves and executes the current external CLI package if it is not already installed locally.
4. The external search pr
...[truncated 1246 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the skills CLI to a specifically reviewed version rather than invoking an unversioned package, for example through a controlled project dependency and lockfile.
  2. Verify package integrity and provenance using registry integrity metadata, signatures, checksums, and trusted publisher information where available.
  3. Restrict skill discovery and installation to an explicit allowlist of trusted organizations and repositories.
  4. Require immutable commit hashes or signed release tags instead of mutable branches or unpinned repository references.
  5. Review downloaded skill files and any installation hooks before executing or installing them.
  6. Install skills locally and with the minimum necessary scope by default. Avoid -g unless global installation is explicitly required.
  7. Remove -y and require informed user confirmation that identifies the exact source, version or commit, requested scope, and reviewed contents.
  8. Separate discovery from installation: searching may be automated, but installation should require a distinct approval step.
  9. Run package retrieval and inspection in a restricted environment with limited filesystem, network, credential, and process permissions.
  10. Maintain an audit record containing the selected repository, immutable revision, integrity value, review result, and approving user.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level description says the skill should be used for broad prompts like 'how do I do X' and general interest in extending capabilities, which are common everyday phrases rather than narrowly scoped triggers. That can cause unintended invocation of this skill in benign conversations, increasing the chance the agent recommends or initiates package installation flows when the user only wanted general advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed activation conditions are broad and ambiguous, including questions like 'can you do X' or vague statements about wanting help in a domain. In this skill's context, over-triggering is more dangerous because the skill steers users toward executing third-party package-manager commands and installing code, so false activations can translate into unnecessary exposure to supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a specific package version, which allows whatever version is current in the registry at execution time to run. Because this command is a package-manager-style bootstrapper that may fetch and execute remote code, a compromised upstream release, typosquatted dependency path, or malicious update could lead to arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This reference to npx skills is unpinned, so the executed code is not stable or auditable and may change between runs. In a skill whose purpose is discovery and installation of third-party extensions, that increases supply-chain risk because it normalizes executing remote package-manager commands directly from documentation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The npx skills add <package> guidance invokes an unpinned bootstrap tool and then installs additional third-party content, compounding supply-chain exposure. An attacker controlling the resolved package version or a dependency chain could execute arbitrary code before or during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Although npx skills check sounds lower risk than installation, it still relies on executing an unpinned remote package. That means even a 'check' operation can become a code-execution vector if the package version resolved at runtime is malicious or compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

npx skills update is an unpinned remote execution path that can both fetch the latest CLI and trigger updates to installed skills, making it a high-value supply-chain target. A malicious or compromised release could affect all managed skills and the local environment in one step.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The generic npx skills find [query] instruction is another instance of unpinned remote package execution. Because this is presented as a normal discovery action, it lowers user caution around running unaudited code from the network.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The example command npx skills find react performance trains users to run the unpinned package directly for common tasks. Attackers benefit when routine commands are normalized, because users are less likely to scrutinize what code is fetched and executed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This unpinned example command again creates a supply-chain execution risk by resolving whatever version of the package is current. In the context of a skill that helps install other skills, this broadens the blast radius because discovery may be the first step before more dangerous installs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This line continues the same risky pattern: an unpinned npx invocation used as instructional material. Repetition throughout the file makes the unsafe practice systemic rather than incidental.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The install instruction shown in returned results (npx skills add <owner/repo@skill>) combines unpinned CLI execution with installation of third-party code identified dynamically by search results. That creates a realistic path to arbitrary code execution or installation of a malicious skill if the ecosystem or search result is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The user-facing example npx skills add vercel-labs/agent-skills@vercel-react-best-practices still leaves the CLI itself unpinned, so users may trust the skill spec while overlooking that the bootstrap executable is mutable. This can mislead users into believing the command is fully specific when the most privileged part of it is not.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends npx skills add <owner/repo@skill> -g -y, which performs a global installation and suppresses confirmation for third-party code without presenting any warning about trust, permissions, provenance, or review. In a discovery/install skill, this materially increases the risk of accidental or socially engineered installation of malicious skills with user-wide persistence.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

npx skills add <owner/repo@skill> -g -y is especially risky because it executes an unpinned remote CLI, installs a third-party skill globally, and suppresses confirmation prompts. This removes friction at exactly the point where user review is most important and increases the chance of silent system-wide compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The npx skills init instruction also depends on executing an unpinned package from the network. While initialization may seem less dangerous than install/update, it still grants code execution to the fetched package and can establish insecure defaults or malicious scaffolding.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Another unpinned npx skills reference appears in the tips section, reinforcing a pattern of unaudited remote code execution across the document. The cumulative effect is to normalize insecure operational behavior for both users and downstream skill authors.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.