Back to skill

Security audit

typescript-dev

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only TypeScript development skill with purpose-aligned guidance, though users should review commands that fetch remote packages or rewrite project files.

Install if you want an agent to use this TypeScript stack guidance. Before running generated commands, prefer pinned package versions when practical, avoid arbitrary community registries unless you trust the source, review diffs after scaffold/migrate/format commands, and only initialize MCP or deployment tooling when you explicitly intend that integration.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T08 · Insecure Dependencies

Warning
Location
references/shadcn.md:56
Finding

Unpinned shadcn CLI and arbitrary source registries can introduce untrusted code

Content
View full analysis

Vulnerability Details

File Location: references/shadcn.md:56-61, 79-80, 104
Vulnerability Type: Supply-chain execution through mutable package tags and arbitrary registries
Risk Level: Medium

Vulnerable Code

bash
pnpm dlx shadcn@latest init
pnpm dlx shadcn@latest add button card form
pnpm dlx shadcn@latest add button --overwrite
pnpm dlx shadcn@latest add button --dry-run
pnpm dlx shadcn@latest add button --diff
pnpm dlx shadcn@latest add button --view
bash
pnpm dlx shadcn@latest add @acme/button
pnpm dlx shadcn@latest add username/repo/item
pnpm dlx shadcn@latest registry validate
bash
pnpm dlx shadcn@latest mcp init

Technical Analysis

pnpm dlx retrieves and executes a package without establishing it as a reviewed, lockfile-pinned project dependency. The mutable @latest tag means the executed package can differ from the version that existed when the Skill was audited.

The source-registry example also permits code to be copied from an arbitrary GitHub repository directly into a project. Registry components are source code rather than passive assets and may contain malicious imports, build hooks, credential collection, or runtime backdoors. Initializing the MCP integration further exposes registry operations to an AI client, increasing the consequences of insufficient source validation.

These operations are not automatically performed by the Skill, but an agent following the instructions can execute them with the invoking user's filesystem and process permissions.

Attack Path

  1. An attacker compromises the package publishing account, publishes a malicious release selected by @latest, or controls a referenced registry or GitHub repository.
  2. A developer or agent follows the documented pnpm dlx or source-registry command.
  3. The remote CLI executes locally, or untrusted component source is written into the target project.
  4. Malicious code ...[truncated 713 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace shadcn@latest with an exact reviewed version.
  • Enforce lockfiles and package integrity verification where supported.
  • Require --dry-run, --view, or --diff before allowing the CLI to modify project files.
  • Allowlist trusted registries and repository owners; do not recommend arbitrary username/repo/item sources.
  • Review all generated or imported source code before building or executing it.
  • Run registry tooling in a sandbox with restricted filesystem access, no unnecessary secrets, and limited outbound network access.
  • Require explicit user approval before initializing MCP integrations or applying registry content.

T08 · Insecure Dependencies

Warning
Location
references/hono.md:30
Finding

Mutable Hono scaffolder package is downloaded and executed without version pinning

Content
View full analysis

Vulnerability Details

File Location: references/hono.md:30-31
Vulnerability Type: Unpinned remote scaffolder execution
Risk Level: Medium

Vulnerable Code

sh
npm create hono@latest my-app
npm create hono@latest my-app -- --template cloudflare-workers --pm pnpm --install

Technical Analysis

npm create hono@latest downloads and executes the package currently selected by the mutable latest tag. The second command also requests dependency installation, expanding the set of remotely obtained packages and potential lifecycle behavior.

Because no exact version or integrity value is specified, the effective scaffolding code may change after the Skill has been reviewed. A compromised publisher account or malicious release could therefore convert otherwise legitimate setup guidance into a remote code-execution path.

Attack Path

  1. An attacker compromises the scaffolder's publication channel or causes a malicious release to become the version selected by latest.
  2. An agent follows the Skill and executes npm create hono@latest.
  3. The package manager downloads and runs the changed scaffolder.
  4. The scaffolder writes attacker-controlled files and may install further dependencies.
  5. Malicious code executes with the permissions and environment inherited from the invoking user.

Impact Assessment

Exploitation could modify the generated application, execute commands, install additional dependencies, and access data available to the invoking process. The potential scope includes the destination project, adjacent user-accessible files, environment variables, package-manager credentials, and network resources. A backdoor placed in generated code may later be committed or deployed.

Remediation
View remediation

Remediation Suggestions

  • Replace hono@latest with an exact, reviewed scaffolder version.
  • Document the expected package name, version, and integrity information.
  • Run scaffolding in a new, isolated directory without production credentials.
  • Separate scaffolding from dependency installation so generated files can be reviewed first.
  • Use package-manager controls that restrict or disable lifecycle scripts when feasible.
  • Review the generated manifest and lockfile before installing dependencies or executing the generated application.

T08 · Insecure Dependencies

Note
Location
references/biome.md:35
Finding

Biome installation relies on a mutable latest release

Content
View full analysis

Vulnerability Details

File Location: references/biome.md:35-36
Vulnerability Type: Unpinned initial dependency retrieval and immediate project rewrite
Risk Level: Low

Vulnerable Code

bash
pnpm add --save-dev --save-exact @biomejs/biome@latest
pnpm biome migrate --write

Technical Analysis

Although --save-exact records the resolved version after installation, the initial resolution still uses the mutable @latest tag. Consequently, the package selected at execution time is not fixed by the audited documentation. The subsequent migration command immediately runs the downloaded tooling with write access to the project.

A compromised or malicious latest release could alter more files than intended, execute package lifecycle behavior where enabled, or abuse the permissions and environment of the invoking process.

Attack Path

  1. An attacker compromises the package release channel or publishes a malicious version selected by @latest.
  2. A developer or agent executes the documented installation command.
  3. The package manager retrieves the malicious version.
  4. The developer or agent executes pnpm biome migrate --write.
  5. The downloaded tool runs with project write access and can introduce malicious configuration or source modifications.

Impact Assessment

The primary scope is the current project and any files accessible to the invoking user. A malicious package could tamper with source or configuration, collect accessible environment data, or implant changes that later run in CI or production. Exploitation requires the documented commands to be executed and compromise of the upstream distribution path.

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact reviewed Biome version.
  • Verify the resolved package and integrity metadata before executing migration commands.
  • Install dependencies with lifecycle scripts disabled where compatible.
  • Commit and inspect the lockfile before running the tool.
  • Run migration in a clean branch or disposable workspace and review the full diff before accepting changes.
  • Avoid exposing unrelated credentials or production secrets to formatting and migration processes.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description says to use the skill when 'setting up or working in a TypeScript project,' followed by a very broad list of common development activities. For a manifest-scoped trigger description, this is ambiguous and could overlap with many ordinary TypeScript tasks without clearly delimiting when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 27)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 31)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 54)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 147)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file includes commands that modify project files (biome check --write . and --write --unsafe) and describes that assists can rewrite files, but it does not give a general up-front warning that these commands will change files in-place. The note to review diffs applies only to unsafe fixes, so a reader may miss that the standard --write path is also mutating.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The documented pnpm biome migrate --write command updates configuration files, but the markdown does not explicitly warn that it rewrites files automatically. Although the command name implies writes, the skill description criteria call for warning users when behavior could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.