Back to skill

Security audit

KSE CLI 开发工作流

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese-language guide for using the KSE CLI, with the main caution being an unpinned global npm install.

Install only if you are comfortable adding the kiro-spec-engine npm package as a global CLI. Prefer checking the package source, pinning a reviewed version, and avoiding elevated privileges when installing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis
Remediation
View remediation
``` 2. Prefer a project-local dependency over global installation, and commit the generated lockfile so that package resolution is reproducible. 3. Use `npm ci` for repeatable installation from a reviewed lockfile where applicable. 4. Verify package provenance, publisher identity, release signatures or attestations, and expected integrity metadata before recommending installation. 5. Review the package's dependency tree and npm lifecycle scripts before approving a version. 6. If global installation is operationally necessary, pin the exact version, avoid elevated privileges, and document a controlled upgrade and security-review process. 7. Consider disabling lifecycle scripts during initial inspection with `--ignore-scripts`, then enable them only after confirming that required scripts are trustworthy. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description and the entire skill content are written only in Chinese, which imposes a language constraint on users without any opt-in or alternative locale. Under the policy, language restrictions must either offer user choice or be clearly justified as region-specific, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written only in Chinese ("基于 kiro-spec-engine (kse) 的 CLI 开发工作流"), which signals a language-specific presentation without any indication of user choice or opt-in. Under the language/locale policy rule, this is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.