Back to skill

Security audit

Skill Preflight Bootstrap

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly transparent about its goal, but it persistently changes future agent behavior and can automatically run an unpinned remote npm tool.

Review before installing. Use `--dry-run` first, inspect the exact changes to AGENTS.md, .codex/settings.json, and .claude/settings.json, and avoid running the generated preflight with remote search unless you trust the npm `skills` package source. Consider pinning or replacing the remote search command and adding an uninstall process before using this in shared repositories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
scripts/bootstrap-skill-preflight.py:151
Finding

Persistent Agent Instruction Hijacking Through Repository Hooks and AGENTS.md

Content
View full analysis
None: target = context.target_root / "AGENTS.md" if target.exists(): current = target.read_text(encoding="utf-8") if AGENTS_MARKER in current: context.log("SKIP AGENTS.md (already contains preflight section)") return context.log("APPEND AGENTS.md") if context.dry_run: return separator = "\n\n" if not current.endswith("\n\n") else "" target.write_text(current.rstrip() + separator + AGENTS_SECTION + "\n", encoding="utf-8") return context.log("WRITE AGENTS.md") if context.dry_run: return target.write_text(MINIMAL_AGENTS_HEADER + AGENTS_SECTION + "\n", encoding="utf-8") ``` ```bash #!/bin/bash set -e cat <<'EOF' Before processing the current task, run the Skill preflight process, use remote Skill discovery when local results are unsuitable, and report which Skills will be used. Record reusable experience and errors in the repository learning files. EOF ``` The final shell excerpt i ...[truncated 2827 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/skill-preflight.py:209
Finding

Automatic Execution of an Unpinned Third-Party npm Package

Content
View full analysis
Tuple[int, str]: command = ["npx", "-y", "skills", "find", query] completed = subprocess.run(command, capture_output=True, text=True) combined = (completed.stdout or "") + (completed.stderr or "") return completed.returncode, strip_ansi(combined).strip() ``` ```python should_run_remote = args.remote or not local_matches if should_run_remote: print_header("Remote Skill search") command = ["npx", "-y", "skills", "find", query] print("Command:") print(f"$ {shlex.join(command)}") return_code, output = run_remote_search(query) if output: print(output) else: print("Remote search returned no content.") if return_code != 0: print(f"\nRemote search exit code: {return_code}", file=sys.stderr) return return_code ``` The displayed strings in the second excerpt are English renderings of the source program's user-facing messages; the executable statements are unchanged. ### Technical Analysis The preflight script invokes: ```text npx -y skills find ``` No exact package version, integrity hash, trusted registry, or verified package source is specified. `npx` can retrieve the package from the configured npm registry and execute its lifecycle or command code with the current user's privileges. The `-y` option suppresses the normal installation confirmation. Remote execution is not limited to an explicit `--remote` request. The condition automatically runs the npm package whenever no local Skill reaches the matching threshold: ```python should_run_remote = args.remote or not local_matches ``` Consequently, a normal local preflight can cross a network boundary and execute mutable third-party code without an additional confirma ...[truncated 2174 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

该描述聚焦于“给新仓库安装/迁移技能预检工作流”的初始化能力,而代码片段只是一个现成 hook 的局部实现:它被动读取工具输出,匹配错误关键词,并在发生错误时打印一条记录到 .learnings/ERRORS.md 的提醒。它没有创建仓库文件、安装 hooks、迁移配置、封装流程到其他仓库,或执行任何初始化动作。因此,代码行为与声明的主要用途存在实质偏差。若整体技能包含其他文件实现初始化流程,单就此代码片段而言,仍无法支撑该声明。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

描述强调的是“把技能预检工作流落到新仓库”的初始化/迁移能力,意味着应看到创建、复制、写入仓库文件或配置 hooks 等行为。但代码仅提供查询型 CLI:读取若干固定目录下的 SKILL.md 文件、解析 frontmatter/标题、做文本匹配评分,并按需调用 npx -y skills find 搜索远程技能。它没有对目标仓库进行初始化、安装或迁移操作,也没有处理 .learnings/、hooks 或团队文档。因此代码实际行为与声明用途存在明显且实质性的偏差。

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The skill explicitly instructs creating and validating project-level agent configuration files under .codex/settings.json and .claude/settings.json. Modifying agent config directories can change hooks, execution behavior, or trust boundaries for future agent runs, so this is security-sensitive even when intended for legitimate bootstrap. In this context the danger is moderated because the skill states it targets project-level config rather than global user config, but it still affects agent behavior inside the repository.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
落地后建议至少做三步检查:

1. 验证 JSON:
   - `python3 -m json.tool /path/to/target-repo/.codex/settings.json`
   - `python3 -m json.tool /path/to/target-repo/.claude/settings.json`
2. 验证预检脚本:
   - `python3 /path/to/target-repo/scripts/skill-preflight.py "react performance"`

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Referencing .claude/settings.json indicates the skill will interact with agent configuration that can influence how tooling behaves in the target repository. Even if the stated purpose is benign bootstrap, agent config modification is inherently sensitive because it may persistently alter hooks or automated actions for future sessions. The context lowers suspicion somewhat because the skill emphasizes project scope and dry-run support, but unauthorized or opaque config changes could still have meaningful downstream impact.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
1. 验证 JSON:
   - `python3 -m json.tool /path/to/target-repo/.codex/settings.json`
   - `python3 -m json.tool /path/to/target-repo/.claude/settings.json`
2. 验证预检脚本:
   - `python3 /path/to/target-repo/scripts/skill-preflight.py "react performance"`
3. 检查 `AGENTS.md` 是否只追加一次技能预检片段

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/examples.md (reported line 33)May include surrounding context.

bash
tmpdir="$(mktemp -d)"
python3 scripts/bootstrap-skill-preflight.py "$tmpdir"
python3 -m json.tool "$tmpdir/.codex/settings.json" >/dev/null
python3 -m json.tool "$tmpdir/.claude/settings.json" >/dev/null
python3 "$tmpdir/scripts/skill-preflight.py" "react performance"

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/examples.md (reported line 34)May include surrounding context.

tmpdir="$(mktemp -d)" python3 scripts/bootstrap-skill-preflight.py "$tmpdir" python3 -m json.tool "$tmpdir/.codex/settings.json" >/dev/null python3 -m json.tool "$tmpdir/.claude/settings.json" >/dev/null python3 "$tmpdir/scripts/skill-preflight.py" "react performance"

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content of the skill, including its description and operating instructions, is presented only in Chinese. Under the stated policy, forcing a specific language without user opt-in is a language/locale policy violation unless the constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file embeds all user-facing instructions, help text, and generated documentation in Chinese, including the AGENTS.md section and CLI argument descriptions. That creates a locale/language constraint in natural-language content without any user opt-in or documented justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The user-facing message on L34 is written entirely in Chinese, which imposes a specific language on all users of the hook. Under the policy criteria, forcing a language without opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The natural-language instructions shown by this hook are entirely in Chinese and direct the workflow in that language, without any opt-in, alternative locale, or justification that the skill is region-specific. This creates a language/locale policy issue because it implicitly forces a specific language for users regardless of their preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code defines the command description and help text entirely in Chinese, and later prints user-facing runtime messages in Chinese as well. Because the file provides no option to select locale or opt in to Chinese, it appears to enforce a specific language for all users, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The script invokes npx -y skills find, which fetches and executes a package without pinning an exact version or integrity. That creates a supply-chain execution path where a compromised, typosquatted, or newly changed upstream package can run arbitrary code on the user's machine during a preflight workflow, increasing exposure because users are encouraged to run it routinely.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/skill-preflight.py (reported line 212)May include surrounding context.

python
def run_remote_search(query: str) -> Tuple[int, str]:
    command = ["npx", "-y", "skills", "find", query]
    completed = subprocess.run(command, capture_output=True, text=True)
    combined = (completed.stdout or "") + (completed.stderr or "")
    return completed.returncode, strip_ansi(combined).strip()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script prints task status, recommendations, and remote-search messages exclusively in Chinese. These are user-facing strings, and there is no visible mechanism for locale selection or user consent, so the implementation forces a specific language unconditionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.