T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:14- Finding
Runtime Retrieval and Execution of a Mutable GitHub Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent transcription purpose, but it tells agents to execute mutable GitHub-hosted code with an API key and sends sensitive values as URL query parameters.
Review before installing. Use only media you are allowed to submit, prefer non-sensitive or short-lived media URLs, and avoid exposing broad environment secrets to the CLI. The publisher should replace the GitHub `npx` tag with an immutable reviewed package or commit and move secrets/media URLs out of query parameters.
SKILL.md:14Runtime Retrieval and Execution of a Mutable GitHub Dependency
references/api.md:5API Key and Sensitive Media URLs Transmitted in Query Parameters
The skill instructs users to execute code directly from a GitHub repository via npx -y github:...#v1.1.0, which is a remote code execution path and not a securely pinned package artifact. Although a tag is present, Git tags can be moved and GitHub-sourced installs bypass the stronger integrity guarantees of registry-published packages with lockfile or digest verification, creating a supply-chain risk. In this skill context, the command is especially sensitive because it processes external media URLs and is expected to access HOTBEE_API_KEY from the local environment.
The documentation instructs users to run npx -y github:...#v1.1.0, which fetches and executes code directly from a GitHub repository rather than a registry package with stronger provenance controls. Even though a tag is specified, tags can be moved or the referenced repository can be compromised, so this creates a supply-chain risk where users may execute unexpected code.
No suspicious patterns detected.