Back to skill

Security audit

Html Coder Paid

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be an HTML development helper, but it requests broad command, file-write, and API authority and includes unsafe install/elevation guidance that users should review first.

Review this skill before installing. Use it only in a restricted workspace, avoid running the agent or generated commands as administrator, and do not follow the unpinned global Lighthouse install guidance unless you replace it with a pinned, project-local dependency. Require explicit approval before any file writes, command execution, or external API calls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:228
Finding

Unpinned Package Retrieval and Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 228
Vulnerability Type: Unpinned third-party dependency retrieval and execution
Risk Level: Medium

Vulnerable Code

bash
npx lighthouse https://example.com --output html --output-path ./report.html

Technical Analysis

The documented npx lighthouse command does not specify an audited package version. If Lighthouse is unavailable locally, npx may retrieve the currently resolved package and its dependency tree from the configured npm registry before executing it.

Because registry content is mutable after the Skill itself has been reviewed, the effective executable payload is not fully represented by the audited project. A compromised package release, npm account, registry mirror, or transitive dependency could therefore introduce arbitrary code. The Lighthouse operation is relevant to the declared performance-auditing functionality, but unpinned package execution is not the minimum-risk implementation.

Attack Path

  1. An attacker compromises a relevant npm package, maintainer account, registry path, or transitive dependency.
  2. A malicious package version becomes the version resolved by the unpinned npx lighthouse command.
  3. A user or Agent follows the Skill documentation and runs the command.
  4. npx retrieves the mutable package content when no suitable local installation is available.
  5. Malicious installation or runtime code executes with the permissions and environment of the invoking account.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the invoking user's privileges. Depending on sandboxing and host permissions, the compromised dependency could read or alter accessible project files, inspect process environment data, create network connections, modify user-scoped configuration, or tamper with generated audit reports. The Skill does not itself demonstrate such malicious behavior; ...[truncated 62 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin Lighthouse to a specifically reviewed version rather than resolving the latest available release.
  • Install dependencies from a committed lockfile with integrity hashes.
  • Prefer a project-local development dependency over implicit npx downloading.
  • Use a command that refuses automatic package installation when supported.
  • Run Lighthouse in a container or restricted sandbox with only the required output directory mounted as writable.
  • Restrict access to credentials, environment variables, unrelated files, and unnecessary network destinations.
  • Establish a dependency-update process that includes provenance, vulnerability, and integrity review before changing the pinned version.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:290
Finding

Unsafe Recommendation to Install Lighthouse Globally Without Version Pinning

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 290
Vulnerability Type: Unpinned global third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
npm install -g lighthouse

Technical Analysis

The installation guidance retrieves Lighthouse and its transitive dependencies without specifying a version or integrity-controlled lockfile. The -g option installs the package globally rather than limiting it to the project. npm installation may execute package lifecycle scripts, and a global installation leaves executable artifacts outside the audited project directory.

Lighthouse is a legitimate and relevant optional dependency, but global, unpinned installation unnecessarily increases the persistence and scope of a potential supply-chain compromise.

Attack Path

  1. An attacker compromises Lighthouse, a transitive dependency, a package-maintainer account, or the registry source used by npm.
  2. The unpinned command resolves to attacker-controlled package content.
  3. A user follows the Skill's setup instructions and performs the global installation.
  4. Malicious lifecycle code may run during installation.
  5. The installed global executable may continue to run attacker-controlled code during later Lighthouse invocations.

Impact Assessment

Exploitation could execute arbitrary code with the privileges of the account running npm. The global installation may also persist a compromised executable beyond the current project and expose other projects or later sessions that invoke the same command. If a user combines this guidance with the separate recommendation to run as an administrator, the consequences could expand to system-wide file modification and privileged code execution.

Remediation
View remediation

Remediation Suggestions

  • Replace the global installation with a project-local, version-pinned development dependency.
  • Commit and enforce an npm lockfile containing integrity metadata.
  • Disable or tightly control dependency lifecycle scripts where operationally possible.
  • Never install the package with administrator or root privileges.
  • Execute the tool in a sandbox with minimal filesystem and network access.
  • Verify package provenance and review transitive dependency changes during upgrades.
  • Remove obsolete global installations from development and CI environments.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:459
Finding

Blanket Administrator Escalation for Routine File Permission Errors

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 459, 477, and 490
Vulnerability Type: Unnecessary privilege-escalation guidance
Risk Level: Medium

Vulnerable Code

The following troubleshooting entry is repeated at lines 459, 477, and 490. English translation of the source entry:

text
Permission denied | The current user lacks read/write permission | Check file permissions and run as administrator

Technical Analysis

The Skill recommends administrator execution as a generic response to insufficient file permissions. HTML generation, workspace-local file processing, WCAG checks, and Lighthouse audits ordinarily require only user-level access to the relevant project and output files.

The guidance does not first require identifying the affected path, correcting ownership, selecting a user-writable output directory, or narrowing permissions to the minimum required resource. Consequently, it may move the complete Agent or command execution context across a least-privilege boundary without a task-specific justification.

Attack Path

  1. A routine operation encounters a permission error, such as an unwritable report path or globally protected installation directory.
  2. The user follows the repeated troubleshooting advice and reruns the Agent, npm operation, or generated command with administrator privileges.
  3. An unsafe dependency, malformed generated command, or other compromised process then executes in the elevated context.
  4. The process gains access to privileged files and system-level configuration that were unnecessary for the original HTML-development task.

This finding does not establish an automatic privilege-escalation exploit in the Skill. The risk is that the documentation encourages the user to grant excessive privileges, thereby amplifying another failure or compromise.

Impact Assessment

Elevated execution could permit system-wide file creation or modification, ins ...[truncated 283 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove all three blanket recommendations to run as an administrator.
  • Direct users to identify the exact inaccessible path and determine why access is required.
  • Use workspace-local input, dependency, cache, and report directories owned by the current user.
  • Prefer user-scoped or project-local package installation.
  • Correct narrowly scoped ownership or permissions instead of elevating the entire process.
  • Explicitly prohibit running the Agent, npm, Lighthouse, or generated commands as root or administrator unless a separately reviewed operation has a documented requirement.
  • If elevation is exceptionally necessary, require explicit user approval and elevate only a narrowly constrained command rather than the complete Agent session.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (9)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
role="img"
      aria-label="月度销售趋势柱状图,显示1月至6月的销售数据"
    >
      <!-- 降级内容:不支持Canvas时显示 -->
      <table>
        <caption>月度销售数据</caption>
        <thead><tr><th>月份</th><th>销售额</th></tr></thead>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
role="img"
      aria-label="月度销售趋势柱状图,显示1月至6月的销售数据"
    >
      <!-- 降级内容:不支持Canvas时显示 -->
      <table>
        <caption>月度销售数据</caption>
        <thead><tr><th>月份</th><th>销售额</th></tr></thead>

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares system command execution as a capability even though its stated purpose is HTML development assistance. In combination with the listed exec tool and vague invocation guidance, this creates an unnecessary privilege expansion where a content-generation skill could run arbitrary local commands, affecting files, processes, or secrets on the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill's display name and summaries are presented only in Chinese, and the examples also default to Chinese locale content. There is no statement that users may choose another language or locale, which can violate a language-choice policy when the skill is not clearly limited to a Chinese-only regional use case.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation guidance is broad and unspecific, effectively suggesting the skill can be called whenever needed without defining scope, required inputs, or prohibited operations. Ambiguous trigger conditions increase the chance of overbroad use, including running higher-risk capabilities such as file writes or command execution in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill recommends running npx lighthouse without pinning an exact package version, which allows execution of whatever version resolves at runtime. In an agent context with exec capability, this creates supply-chain risk and can lead to unreviewed code execution if the upstream package or dependency graph changes or is compromised.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation claims the skill is driven by pure Markdown instructions and needs no extra configuration, yet elsewhere it describes command execution and external/API behavior. This inconsistency can mislead users and reviewers about the skill's actual trust boundary and side effects, increasing the risk of unsafe execution under false assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents file processing, API integration, and command execution capabilities but does not present a prominent user warning about their operational impact. In an agent environment, this can cause users to invoke the skill expecting passive guidance while it may instead alter files, execute commands, or transmit data externally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is presented as an HTML/WCAG development tool, but it also advertises generic external API/service integration capabilities unrelated to that narrow purpose. Broadening the operational scope increases the chance the agent will send project content to external services or perform network actions users did not expect from an HTML coding helper.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.