Back to skill

Security audit

Data Privacy Agreement

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed agreement-template helper; its main risk is optional use of remote services or unpinned external install commands, not hidden or malicious behavior.

Before installing, verify the OpenAgreements package/source you use and prefer a pinned release or trusted MCP setup. Review any generated DPA, BAA, or AI addendum with appropriate legal counsel, and do not send unnecessary sensitive data to the remote MCP.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:89
Finding

Unpinned Third-Party Package Installation Creates a Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:89
  • template-filling-execution.md:80-83
  • CONNECTORS.md:17-19

Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:89:

markdown
(install: `npx skills add open-agreements/open-agreements`).

template-filling-execution.md:80-83:

markdown
- Easiest: configure the remote MCP (see Step 1)
- Alternative: install Node.js 20+ and `npm install -g open-agreements`

CONNECTORS.md:17-19:

markdown
### Alternative: Local CLI

For fully local execution (no network calls during fills), install [`open-agreements` from npm](https://www.npmjs.com/package/open-agreements). Requires Node.js >= 20. See the [README](https://github.com/open-agreements/open-agreements#use-with-claude-code) for details.

Technical Analysis

The documented installation commands retrieve mutable third-party content without pinning an exact audited version or verifying its integrity. The project does not include a lockfile, checksum, signature, provenance requirement, or vendored implementation against which the downloaded content can be validated.

In particular, npm install -g open-agreements resolves the package version available under the package registry's current metadata. npm packages may contain installation lifecycle scripts that execute during installation. A global installation also makes the resulting executable broadly available in the user's environment.

The npx skills add open-agreements/open-agreements instruction similarly retrieves external skill content by a mutable package or repository identifier rather than an immutable audited revision. Consequently, the code or instructions installed when a user follows the documentation may differ from the content that was originally reviewed.

This is a supply-chain weakness rather than evidence that the referenced ...[truncated 1741 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an exact reviewed release rather than resolving the latest version:

    bash
    npm install --global --ignore-scripts open-agreements@<audited-exact-version>
    

    Only use --ignore-scripts if the audited package does not legitimately require lifecycle scripts.

  2. Avoid global installation where possible. Prefer a project-local dependency installed under a dedicated, least-privileged environment.

  3. Pin skill installation to an immutable release tag or commit digest supported by the installer rather than a mutable repository identifier.

  4. Publish and document cryptographic checksums or signed provenance for approved artifacts. Verify downloaded content before execution.

  5. Use a lockfile with integrity metadata for local dependency installations, and review transitive dependency changes before updating the approved version.

  6. Document the expected package publisher, source repository, exact version, and verification procedure so users can detect typosquatting or registry compromise.

  7. Run installation and document generation as a non-privileged user without unnecessary access to credentials or sensitive directories.

  8. Establish a controlled upgrade process that audits each new package version and updates the pinned version only after review.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · template-filling-execution.md (reported line 58)May include surrounding context.

If Local CLI: Write values to a per-run temporary JSON file with restrictive permissions:

bash
VALUES_FILE="$(mktemp /tmp/oa-values.XXXXXX.json)"
chmod 600 "$VALUES_FILE"
trap 'rm -f "$VALUES_FILE"' EXIT

cat > "$VALUES_FILE" << 'FIELDS'

Static analysis

No suspicious patterns detected.