Back to skill

Security audit

tanstack

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent TanStack documentation skill, but it includes a few unsafe code examples and mutable package-execution commands that users should review before relying on it.

Review the examples before copying them into production. Pin scaffold/package commands to reviewed versions, do not put secrets in query strings, confine any file-serving route to an allowlisted base directory, and add authorization plus confirmation or undo patterns around destructive mutations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:288
Finding

Mutable “latest” package versions are downloaded and executed

Content
View full analysis
Remediation
View remediation
create ``` 2. Keep the version consistent with the versions declared in the Skill metadata. 3. Review package provenance, publisher identity, release signatures or attestations, and registry integrity before approving updates. 4. Use lockfiles and integrity hashes for subsequent dependency installation. 5. Perform version upgrades through an explicit review process rather than automatically following a mutable distribution tag. 6. Where feasible, run scaffolding tools in an isolated workspace with restricted credentials and no unnecessary secrets in the environment. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/start-guide.md:136
Finding

Server-side secret is transmitted in a URL query string

Content
View full analysis
{ return fetch(`/api/users?key=${process.env.SECRET}`) }) export const Route = createFileRoute('/users')({ loader: () => getUsers(), }) ``` ### Technical Analysis Using `createServerFn()` appropriately prevents `process.env.SECRET` from being included directly in the client bundle. However, the example then interpolates that secret into a URL query parameter. URL query strings are routinely captured by server access logs, reverse proxies, application performance monitoring systems, tracing platforms, debugging tools, and error reports. If the request is redirected, the URL may also be propagated to another endpoint. Consequently, server-side execution alone does not make query-string credentials safe. The comment labels this pattern as “CORRECT,” which may encourage users or coding agents to reproduce it without recognizing the logging risk. Authentication material should be carried in a protected request header or another mechanism specifically designed for credentials. ### Attack Path 1. A developer or agent copies the documented server-function pattern. 2. The server reads `process.env.SECRET` and inserts it into the request URL. 3. The application server, reverse proxy, observability agent, or upstream API records the complete URL. 4. The credential remains in logs, traces, monitoring exports, backups, or diagnostic reports. 5. An attacker or unauthorized operator with access to one of those systems extracts the `key` value. 6. The attacker reuses the credential against the protected API until it is revoked or expires. ### Impact Assessment Exposure grants the attacker whatever authorization is associated with `process.env.SEC ...[truncated 460 chars]
Remediation
View remediation
{ return fetch('/api/users', { headers: { Authorization: `Bearer ${process.env.SECRET}`, }, }) }) ``` 2. Require HTTPS for the upstream request. 3. Ensure reverse proxies, application logs, and tracing systems redact authorization and other sensitive headers. 4. Use a narrowly scoped credential with rotation and expiration support. 5. Check the upstream response status before returning or parsing data. 6. Revise the documentation comment to explain that server functions protect secrets from client bundles but do not make query-string credentials safe. 7. Audit existing logs and observability stores if this pattern has already been deployed, then rotate any potentially recorded credential. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (45)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
- `optimistic-updates.md` - Optimistic UI, rollback, undo

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
- `router-ssr.md` - SSR setup, streaming, hydration

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 382)May include surrounding context.

md
- `start-guide.md` - Complete Start reference with all patterns

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 384)May include surrounding context.

md
- `middleware.md` - sendContext, custom fetch, global config

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 386)May include surrounding context.

md
- `server-routes.md` - Dynamic params, wildcards, pathless layouts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/server-functions.md (reported line 736)May include surrounding context.

md
## Best Practices

1. **Always use server functions for sensitive operations, and authorize inside them.** Route loaders are isomorphic (run on both server and client). Never access secrets, database connections, or server-only APIs directly in loaders - wrap them in `createServerFn()`. Because a server function is an endpoint reachable independently of any route, enforce auth in the handler or its middleware - `beforeLoad` route guards are UX, not the data boundary.

2. **Validate all input with schemas.** Server functions cross a network boundary. Use Zod, Valibot, or ArkType to validate data at runtime, not just TypeScript types.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ssr-modes.md (reported line 1108)May include surrounding context.

}

text

### .env File Hierarchy

Files are loaded in this order (later files override earlier ones):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ssr-modes.md (reported line 1113)May include surrounding context.

}

text

### .env File Hierarchy

Files are loaded in this order (later files override earlier ones):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ssr-modes.md (reported line 1114)May include surrounding context.

text
.env                # Default variables (commit to git)
.env.development    # Development-specific
.env.production     # Production-specific
.env.local          # Local overrides (add to .gitignore)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ssr-modes.md (reported line 1115)May include surrounding context.

text
.env                # Default variables (commit to git)
.env.development    # Development-specific
.env.production     # Production-specific
.env.local          # Local overrides (add to .gitignore)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ssr-modes.md (reported line 1116)May include surrounding context.

.env # Default variables (commit to git) .env.development # Development-specific .env.production # Production-specific .env.local # Local overrides (add to .gitignore)

text

### Type Safety for Environment Variables

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ssr-modes.md (reported line 1231)May include surrounding context.

6. Keep Secrets Server-Side

Never use VITE_ prefix for sensitive values. Access secrets via process.env inside server functions:

tsx
// WRONG: secret in client bundle

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · CHANGELOG.md (reported line 54)May include surrounding context.

md
### Added
- Query: `useIsFetching` / `useIsMutating` for app-wide loading/mutating indicators
  (query-guide.md).
- Query: `maxPages` option to cap stored/refetched pages in infinite queries
  (infinite-queries.md).
- Query: `usePrefetchQuery` / `usePrefetchInfiniteQuery` render-phase prefetch hooks,
  distinct from the imperative `queryClient.prefetchQuery` (query-performance.md).

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/infinite-queries.md (reported line 592)May include surrounding context.

md
### Added
- Query: `useIsFetching` / `useIsMutating` for app-wide loading/mutating indicators
  (query-guide.md).
- Query: `maxPages` option to cap stored/refetched pages in infinite queries
  (infinite-queries.md).
- Query: `usePrefetchQuery` / `usePrefetchInfiniteQuery` render-phase prefetch hooks,
  distinct from the imperative `queryClient.prefetchQuery` (query-performance.md).

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/query-performance.md (reported line 736)May include surrounding context.

md
### Added
- Query: `useIsFetching` / `useIsMutating` for app-wide loading/mutating indicators
  (query-guide.md).
- Query: `maxPages` option to cap stored/refetched pages in infinite queries
  (infinite-queries.md).
- Query: `usePrefetchQuery` / `usePrefetchInfiniteQuery` render-phase prefetch hooks,
  distinct from the imperative `queryClient.prefetchQuery` (query-performance.md).

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx @tanstack/cli@latest create, which pulls and executes whatever version is current at execution time rather than a reviewed, fixed version. That creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious release is published, users of the skill may execute untrusted code immediately.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/infinite-queries.md (reported line 1)May include surrounding context.

md
# Infinite Queries

Infinite queries are used for implementing "load more" and infinite scroll patterns. They allow you to fetch paginated data progressively.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/infinite-queries.md (reported line 564)May include surrounding context.

md
# Infinite Queries

Infinite queries are used for implementing "load more" and infinite scroll patterns. They allow you to fetch paginated data progressively.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/optimistic-updates.md (reported line 239)May include surrounding context.

md
# Infinite Queries

Infinite queries are used for implementing "load more" and infinite scroll patterns. They allow you to fetch paginated data progressively.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/query-guide.md (reported line 439)May include surrounding context.

md
# Infinite Queries

Infinite queries are used for implementing "load more" and infinite scroll patterns. They allow you to fetch paginated data progressively.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/query-invalidation.md (reported line 321)May include surrounding context.

md
# Infinite Queries

Infinite queries are used for implementing "load more" and infinite scroll patterns. They allow you to fetch paginated data progressively.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/query-performance.md (reported line 350)May include surrounding context.

md
# Infinite Queries

Infinite queries are used for implementing "load more" and infinite scroll patterns. They allow you to fetch paginated data progressively.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/query-typescript.md (reported line 347)May include surrounding context.

md
# Infinite Queries

Infinite queries are used for implementing "load more" and infinite scroll patterns. They allow you to fetch paginated data progressively.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/infinite-queries.md (reported line 3)May include surrounding context.

md
# Infinite Queries

Infinite queries are used for implementing "load more" and infinite scroll patterns. They allow you to fetch paginated data progressively.

## Basic Infinite Query

Static analysis

No suspicious patterns detected.