Back to skill

Security audit

Cuihua Dependency Updater

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a dependency updater, but it overstates safety features and may lead an agent to make package changes without enough reliable checks or user control.

Review this skill carefully before installing. Treat its output as informational only, require explicit approval before any npm update, npm audit fix, package.json, lockfile, or changelog change, and run your own tests and vulnerability checks before accepting dependency updates.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill markets itself as performing intelligent dependency updates, security scanning, testing, rollback, and yarn support, but the provided content is largely descriptive and does not demonstrate those capabilities. This can mislead users into relying on nonexistent safety controls, causing unsafe dependency changes or a false sense of security during maintenance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes actions like updating dependencies, running tests, rolling back state, and generating changelog files without clearly warning that these operations execute commands and modify the user's project. In an agent setting, this can lead users to authorize potentially disruptive actions without informed consent, risking codebase changes, dependency drift, or CI breakage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises safety checks, breaking-change detection, and automated testing, but the implementation only runs npm outdated --json and classifies updates by comparing major versions. This can mislead users into trusting the tool's output as a safety assessment, causing risky dependency updates to be treated as safe without validating advisories, changelogs, compatibility, or test results.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code explicitly uses a 'Simple heuristic' that treats non-major updates as safe, which is not a reliable proxy for compatibility or security. In a dependency-updating skill, this context makes the issue more dangerous because users may rely on the 'safe' label to make automated or semi-automated update decisions that can still introduce regressions or unresolved vulnerabilities.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
updater.js:8