Back to skill

Security audit

Oracle

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed helper for running an external review CLI, with normal but meaningful privacy and supply-chain cautions.

Before installing or using this skill, consider pinning @steipete/oracle to a reviewed exact version or installing it through a locked project dependency. Use dry-run and files-report first, attach only necessary files, redact secrets, and be careful with browser sessions, remote-host mode, and API runs that may cost money or expose selected code to external model providers.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Third-Party Package Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29–42
Vulnerability Type: Unpinned package execution through npx -y
Risk Level: Medium

Vulnerable Code Snippet

markdown
- Show help (once/session):
  - `npx -y @steipete/oracle --help`

- Preview (no tokens):
  - `npx -y @steipete/oracle --dry-run summary -p "<task>" --file "src/**" --file "!**/*.test.*"`
  - `npx -y @steipete/oracle --dry-run full -p "<task>" --file "src/**"`

- Token/cost sanity:
  - `npx -y @steipete/oracle --dry-run summary --files-report -p "<task>" --file "src/**"`

- Browser run (main path; long-running is normal):
  - `npx -y @steipete/oracle --engine browser --model gpt-5.2-pro -p "<task>" --file "src/**"`

- Manual paste fallback (assemble bundle, copy to clipboard):
  - `npx -y @steipete/oracle --render --copy -p "<task>" --file "src/**"`

Technical Analysis

The documented commands invoke npx with the automatic-confirmation option (-y) and identify the package only as @steipete/oracle, without an exact version. Consequently, package resolution can retrieve and execute whichever release the configured npm registry currently resolves.

The reviewed project contains no package lockfile, integrity hash, vendored package source, or other mechanism that binds these commands to an audited artifact. An upstream account compromise, malicious package release, registry compromise, or compromised transitive dependency could therefore alter the code executed after this skill has been reviewed.

Because npm package code runs with the privileges of the user invoking npx, both package lifecycle behavior and the CLI entry point fall within the local execution trust boundary. The use of -y removes the normal installation confirmation and makes execution less visible to the user.

Attack Path

  1. An attacker compromises the upstream @steipete/oracle package, one of its depen ...[truncated 1457 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a reviewed exact version in every command, for example:

    sh
    npx --no-install @steipete/oracle
    

    after installing an exact version through the project dependency manifest and lockfile.

  2. Declare the package using an exact version rather than a range:

    json
    {
      "devDependencies": {
        "@steipete/oracle": "REVIEWED_EXACT_VERSION"
      }
    }
    
  3. Commit the generated lockfile and use npm ci in automated or reproducible environments so dependency resolution cannot silently drift.

  4. Verify package provenance and registry integrity before adoption. Review the resolved package, transitive dependencies, lifecycle scripts, publisher identity, and published integrity metadata.

  5. Where a project-local installation is unsuitable, include an exact version in the npx package specification and establish a controlled process for reviewing and updating that version.

  6. Avoid -y where unattended confirmation is unnecessary, so unexpected package installation remains visible to the operator.

  7. Execute the tool with least privilege in an isolated environment. Expose only the files required for the review, avoid secrets in environment variables, and do not provide access to privileged browser profiles or unrelated credentials.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.