Back to skill

Security audit

Develop Web Game

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent web-game testing skill, but it asks agents to perform an unpinned global npm install and keep prompt-bearing progress logs.

Install only if you are comfortable with a skill that runs browser automation against your game, writes local test artifacts, and maintains a progress.md handoff log. Prefer installing Playwright locally with a pinned version instead of following the global @latest npm fallback, and avoid putting secrets or sensitive prompts into progress.md.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:137
Finding

Unpinned Global Installation of a Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 137–140
Vulnerability Type: Supply-chain exposure through a mutable dependency version and global installation
Risk Level: Medium

Vulnerable code:

bash
# If `npx` is missing, install Node/npm and then install Playwright globally:
npm install -g @playwright/mcp@latest

Technical Analysis

The Skill instructs the agent to install @playwright/mcp globally using the mutable latest tag. The package version resolved at execution time can therefore differ from the version assessed when the Skill was audited.

The instruction provides no exact version pin, lockfile, integrity verification, or package-content validation. In addition, npm package installation can invoke package lifecycle scripts with the privileges of the user running npm. The global -g scope also affects the user's wider Node.js environment rather than an isolated project dependency tree.

This is a supply-chain weakness rather than evidence that the currently published package is malicious. Exploitation requires compromise or unexpected modification of the package release, its publishing account, or the configured npm registry.

Attack Path

  1. Playwright or npx is unavailable in the environment.
  2. The agent follows the prerequisite instructions and installs Node.js/npm.
  3. The agent executes npm install -g @playwright/mcp@latest.
  4. npm resolves latest from the configured registry at installation time.
  5. If the resolved package or one of its dependencies has been compromised, malicious package content or lifecycle scripts execute under the invoking user's account.
  6. Because installation is global, malicious or incompatible files may affect commands and packages outside the audited project.

Impact Assessment

A compromised dependency could execute code with the privileges of the user invoking npm. Depending on that user's permissions and environment, thi ...[truncated 454 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact, reviewed package version.
  • Prefer a project-local development dependency rather than a global installation.
  • Commit a lockfile and install with npm ci to enforce the reviewed dependency graph.
  • Verify package provenance and registry configuration before installation.
  • Preserve and validate npm integrity metadata.
  • Disable lifecycle scripts when they are unnecessary, for example with --ignore-scripts, after confirming that doing so does not break the dependency.
  • Run installation as a non-privileged user in an isolated workspace or container.
  • Document the expected package version and a controlled upgrade-review process.

A safer pattern would be:

bash
npm install --save-dev --save-exact @playwright/mcp@<reviewed-version>
npm ci
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

export WEB_GAME_ACTIONS="$CODEX_HOME/skills/develop-web-game/references/action_payloads.json"

text

User-scoped skills install under `$CODEX_HOME/skills` (default: `~/.codex/skills`).

## Workflow

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
90% confidence
Finding

Instructing the agent to read and preserve the original prompt from progress.md can cause unbounded carry-forward of prior context into future runs. That creates a prompt-injection and context-stuffing risk because adversarial or irrelevant content placed in progress.md may influence later agent behavior, leak prior-task data, or crowd out higher-priority instructions.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
## Progress Tracking

Create a `progress.md` file if it doesn't exist, and append TODOs, notes, gotchas, and loose ends as you go so another agent can pick up seamlessly.
If a `progress.md` file already exists, read it first, including the original user prompt at the top (you may be continuing another agent's work). Do not overwrite the original prompt; preserve it.
Update `progress.md` after each meaningful chunk of work (feature added, bug found, test run, or decision made).
At the end of your work, leave TODOs and suggestions for the next agent in `progress.md`.

Static analysis

No suspicious patterns detected.