Back to skill

Security audit

Audit Trail Logs

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple React UI integration guide with no hidden behavior, though users should review and pin the third-party package before installing it.

Before installing, review the orbcafe-ui package, pin an exact version, use a lockfile, and install in a normal least-privileged project environment. The skill itself does not show hidden or destructive behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Unpinned Third-Party Package Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21-25
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

bash
## Installation

npm install orbcafe-ui
# or
pnpm add orbcafe-ui

Technical Analysis

The skill instructs users to install orbcafe-ui without specifying an exact, reviewed version. Package managers will therefore resolve a currently available version according to their default behavior. The effective dependency content can change after this skill has been reviewed.

npm-compatible package installation may also execute lifecycle scripts supplied by a package or its transitive dependencies. No evidence establishes that the referenced package is currently malicious; however, the unpinned installation process exposes users to future package compromise, malicious releases, dependency confusion within the transitive dependency tree, and unexpected security regressions.

Attack Path

  1. An attacker compromises the package publisher account, package repository, or a transitive dependency.
  2. The attacker publishes a malicious or compromised release.
  3. A user follows the documented npm install orbcafe-ui or pnpm add orbcafe-ui instruction.
  4. The package manager resolves and downloads the compromised release because no reviewed version is pinned.
  5. Malicious lifecycle scripts may execute during installation, or malicious runtime code may execute when the application imports and renders CStandardPage.

Impact Assessment

Installation scripts can generally run with the privileges of the user executing the package manager. A successful supply-chain compromise could read user-accessible source code and credentials, modify project files, implant additional dependencies, or communicate with external systems. Runtime compromise could also affect application data and behavior within the permissions granted to the deployed application. The precise i ...[truncated 117 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin orbcafe-ui to an exact version that has undergone security and provenance review, rather than resolving the latest release implicitly.
  • Commit a package-manager lockfile containing integrity hashes and require reproducible, frozen-lockfile installation in CI and production.
  • Review both the direct package and its transitive dependency tree with dependency auditing and software-composition-analysis tools.
  • Prefer verified package provenance and trusted registries, and configure registry scopes explicitly where applicable.
  • Disable lifecycle scripts during installation when they are not required, such as with npm install --ignore-scripts, and separately review any scripts that must be enabled.
  • Use automated dependency update tooling so version changes are reviewed and tested before adoption.
  • Perform package installation in an isolated, least-privileged environment without access to unnecessary credentials or host resources.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.