Back to skill

Security audit

money-never-sleep

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local portfolio CLI manual, but it asks agents to globally install and run an unpinned third-party package that can mutate financial ledger records.

Review the npm package and publisher before installing, prefer a pinned audited version in an isolated environment, and only let the agent record trades or reset data after you have explicitly confirmed the real-world transaction or destructive action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:65
Finding

Unpinned Third-Party Package Installed Globally

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 65
Vulnerability Type: Unpinned third-party dependency and unaudited binary installation
Risk Level: Medium

Vulnerable Code

bash
npm install -g @never-sleeps/mns-cli

Technical Analysis

The installation procedure retrieves the current published version of @never-sleeps/mns-cli without specifying a version or verifying an integrity digest. It installs the package globally, while the executable package and its source code are not included in the audited project.

Consequently, the effective code executed by the skill can change after this review. A compromised npm account, malicious package release, registry compromise, or compromised transitive dependency could introduce arbitrary installation or runtime behavior. Global installation increases exposure by making the resulting executable available beyond the immediate skill run.

Attack Path

  1. An attacker compromises the npm package, its publisher account, release process, or a dependency used by the package.
  2. The attacker publishes a malicious release under the expected package name.
  3. An agent follows the documented setup command on a system where mns is unavailable.
  4. npm resolves and downloads the attacker-controlled release because no audited version or integrity value is pinned.
  5. Malicious lifecycle scripts or the installed executable run with the permissions of the user invoking npm.
  6. The payload accesses or modifies resources available to that user.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the invoking user's privileges. The resulting scope may include reading or modifying user-accessible files, configuration, portfolio records, environment variables, and credentials; making network requests; and installing a globally accessible command. No evidence establishes administrative privilege escalation, so impact is limite ...[truncated 121 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically audited version, for example:
    bash
    npm install -g @never-sleeps/mns-cli@0.6.0
    
  2. Verify the package archive against a publisher-provided cryptographic digest or trusted signed provenance before installation.
  3. Publish reproducible-build information and checksums for every platform-specific binary.
  4. Avoid global installation where possible. Use a project-local dependency or an isolated, least-privileged environment.
  5. Disable npm lifecycle scripts during installation if the package does not require them:
    bash
    npm install --ignore-scripts @never-sleeps/mns-cli@0.6.0
    
  6. Audit the package contents, installation scripts, binary provenance, and transitive dependencies before approving the pinned release.
  7. Configure automated monitoring for package ownership changes, unexpected releases, integrity changes, and dependency vulnerabilities.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document title and all operational guidance are written as a Chinese-only agent manual, and later sections assume Chinese error text and Chinese trigger phrases. There is no indication that the user can choose another language or that the Chinese-only constraint is optional, which creates a locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.