Back to skill

Security audit

edn

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently maintains a local engineering notebook, with the main caution being its unpinned npx install and update examples.

Before installing, review or pin the skills CLI version used by the npx commands, especially for updates. Expect the skill to read your repository and write a local gitignored engineering-notebook.html plus .gitignore entries; do not install it if you do not want that repository documentation behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:62
Finding

Unpinned Third-Party CLI Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 62–72 and line 80
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: Medium

Complete Code Snippet:

bash
npx skills add skcache/edn
bash
npx skills add skcache/edn -a codex
bash
npx skills add skcache/edn -a claude-code
bash
npx skills update edn

Technical Analysis

The documented installation and update procedures invoke the third-party skills package through npx without specifying an exact reviewed version or an integrity constraint. If the package is not already available locally, npx can resolve and execute a mutable package release from the configured npm registry.

This means the code executed during installation is not contained within, or fixed by, the audited project. A future package release, compromised maintainer account, compromised registry, or malicious dependency introduced into the CLI could change the effective executable payload after this Skill has been reviewed.

No evidence was found that the current skills package is malicious. The issue is the absence of version and integrity controls around executable supply-chain content.

Attack Path

  1. An attacker compromises the package, its publisher account, its dependency chain, or the package source used by the configured npm registry.
  2. The attacker publishes a malicious release that can be selected by the unpinned npx skills command.
  3. A user follows the installation or update instructions in README.md.
  4. npx downloads or resolves the attacker-controlled release.
  5. The package's CLI code, and potentially applicable package installation scripts, execute with the user's privileges.
  6. The malicious code can access or modify resources available to that user before or while performing the expected installation operation.

Impact Assessment

Successful exploitation wou ...[truncated 805 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specifically reviewed version in every installation command, for example:

    bash
    npx --yes skills@<reviewed-version> add skcache/edn
    
  2. Use the same pinned version for agent-specific installation and update operations. Avoid allowing an update command to execute an automatically selected future CLI release.

  3. Document the authoritative npm package name, publisher, source repository, and expected package provenance so users can identify dependency-confusion or impersonation attempts.

  4. Where supported, verify package integrity or provenance before execution. Prefer a lockfile-backed installation workflow for controlled environments.

  5. Review new CLI releases before changing the documented version. Record the reviewed version and update it deliberately rather than relying on mutable registry resolution.

  6. Recommend running installation with a minimally privileged development account and without unnecessary secrets in the process environment.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (19)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 8)May include surrounding context.

html
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="color-scheme" content="dark">
<title>Engineering Notebook</title>
<!--
  edn scaffold — canonical visual system for engineering-notebook.html.

  Usage:

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 203)May include surrounding context.

html
</head>
<body>

<!-- shared arrow markers for all diagrams -->
<svg width="0" height="0" style="position:absolute" aria-hidden="true" focusable="false">
  <defs>
    <marker id="arrow" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 256)May include surrounding context.

html
</div>
    </header>

    <!-- 1. Project Map -->
    <section id="project-map">
      <h2><span class="num">01</span>Project Map</h2>
      <p class="lead">One screen showing the whole system: entry points, components,

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 276)May include surrounding context.

html
<line x1="305" y1="10" x2="305" y2="320" class="edge boundary"/>
          <text x="312" y="20" class="flow-label">trust boundary</text>

          <!-- entry points -->
          <rect x="30"  y="50"  width="190" height="60" rx="8" class="box"/>
          <text x="125" y="82"  text-anchor="middle">Browser clients</text>
          <text x="125" y="99"  text-anchor="middle" class="sub">SPA on /app</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 293)May include surrounding context.

html
<text x="510" y="105" text-anchor="middle">Web / API</text>
          <text x="510" y="122" text-anchor="middle" class="sub">entry · auth · validation</text>

          <!-- data -->
          <rect x="700" y="60"  width="180" height="60" rx="8" class="box"/>
          <text x="790" y="92"  text-anchor="middle">PostgreSQL</text>
          <text x="790" y="108" text-anchor="middle" class="sub">source of truth</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 306)May include surrounding context.

html
<rect x="400" y="190" width="220" height="52" rx="8" class="box ext"/>
          <text x="510" y="222" text-anchor="middle">Identity provider</text>

          <!-- edges -->
          <line x1="620" y1="100" x2="700" y2="100" class="edge"/>
          <line x1="510" y1="150" x2="510" y2="188" class="edge"/>
          <line x1="620" y1="130" x2="700" y2="185" class="edge proposed"/>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 333)May include surrounding context.

html
<svg viewBox="0 0 940 300" role="img" aria-label="System architecture">
          <title>System architecture</title>
          <g font-size="12.5">
            <!-- band 1: presentation -->
            <rect x="20" y="30" width="900" height="64" rx="6" class="band"/>
            <text x="30" y="78" class="sub">Presentation</text>
            <rect x="150" y="38" width="120" height="44" rx="6" class="box"/>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 397)May include surrounding context.

html
</div>
    </section>

    <!-- 4. Key Flows -->
    <section id="key-flows">
      <h2><span class="num">04</span>Key Flows</h2>
      <p class="lead">End-to-end flows. Each: entry, components touched, state read

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 423)May include surrounding context.

html
<line x1="422" y1="70" x2="532" y2="70" class="edge"/>
            <line x1="672" y1="70" x2="822" y2="70" class="edge"/>

            <!-- labels 12px above the line, centered in gaps -->
            <text x="227" y="56" text-anchor="middle" class="flow-label">POST /auth</text>
            <text x="477" y="56" text-anchor="middle" class="flow-label">OIDC flow</text>
            <text x="747" y="56" text-anchor="middle" class="flow-label">create session</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 450)May include surrounding context.

html
<rect x="600" y="48" width="150" height="56" rx="6" class="box"/>
            <text x="675" y="80" text-anchor="middle">PostgreSQL</text>

            <!-- request lane -->
            <line x1="190" y1="76" x2="320" y2="76" class="edge"/>
            <line x1="470" y1="76" x2="600" y2="76" class="edge"/>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 462)May include surrounding context.

html
<text x="675" y="179" text-anchor="middle">Worker (proposed)</text>
            <line x1="675" y1="104" x2="675" y2="150" class="edge proposed"/>

            <!-- labels: centered, 12–16px above their lane -->
            <text x="255" y="62" text-anchor="middle" class="flow-label">POST /invoices</text>
            <text x="535" y="62" text-anchor="middle" class="flow-label">INSERT (tx)</text>
            <text x="255" y="128" text-anchor="middle" class="flow-label">201 invoice</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 492)May include surrounding context.

html
</table>
    </section>

    <!-- 6. Decisions & Tradeoffs -->
    <section id="decisions">
      <h2><span class="num">06</span>Decisions &amp; Tradeoffs</h2>
      <p class="lead">Only decisions a future engineer would reasonably question.</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 522)May include surrounding context.

html
</table>
    </section>

    <!-- 8. Current vs Proposed Architecture -->
    <section id="current-proposed">
      <h2><span class="num">08</span>Current vs Proposed Architecture</h2>
      <p class="lead">Solid = in code today. Dashed = planned, not implemented.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/notebook.html (reported line 577)May include surrounding context.

html
</table>
    </section>

    <!-- 10. Dependencies & External Contracts -->
    <section id="dependencies">
      <h2><span class="num">10</span>Dependencies &amp; External Contracts</h2>
      <p class="lead">Meaningful dependencies plus internal contracts — API shapes,

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to execute npx skills add skcache/edn without pinning an exact package version. This creates a supply-chain risk because future or compromised versions of the skills package could be fetched and executed at install time, and README install commands are often copied directly by users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command again uses npx skills without a pinned version, so users may execute whatever version is current at the time of installation. In a skill-installation context, that is more dangerous because the command is specifically intended to fetch and install agent behavior from an external source, increasing exposure to package or distribution compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The Claude Code installation example repeats the same unpinned npx skills pattern. Because npx may download and immediately run remote package code, an attacker controlling or poisoning the package distribution path could achieve code execution on the user's system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The update command npx skills update edn is also unpinned and therefore pulls mutable code at the moment the command is run. Update flows are especially risky because users are conditioned to trust them and may run them repeatedly, widening the window for a supply-chain compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document declares <html lang="en">, which hard-codes English as the language for the skill artifact. Under the stated policy, forcing a specific language without user opt-in or documented justification is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.