Back to skill

Security audit

TeX Render

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently renders LaTeX into local image files, with no evidence of hidden data theft, persistence, or destructive behavior.

Install only if you are comfortable with automatic local rendering of LaTeX and with running npm install for public npm dependencies. Prefer installing in a low-privilege or isolated workspace, review resolved dependency versions, and disable or avoid the TOOLS.md automatic trigger if you want raw LaTeX or per-use confirmation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:15
Finding

Unpinned npm Dependencies Permit Unreviewed Supply-Chain Changes

Content
View full analysis
npm install ``` ### Technical Analysis All three runtime dependencies use caret version ranges. The project also lacks a committed `package-lock.json`. Consequently, `npm install` can resolve package versions and transitive dependency trees that differ from those reviewed during this audit. A future package release satisfying one of these ranges could introduce malicious or vulnerable code. Installation can also run npm lifecycle scripts and native build operations. The documentation specifically notes that `sharp` may compile during installation, demonstrating that dependency installation is expected to perform executable build activity. No reviewed dependency was proven malicious. The vulnerability is the absence of deterministic dependency resolution and integrity-controlled installation, which exposes users to future registry compromise, maintainer compromise, malicious compatible releases, and unexpected transitive dependency changes. ### Attack Path 1. An attacker compromises a direct or transitive dependency maintainer account, npm publishing token, or package release process. 2. The attacker publishes a malicious version that satisfies one of the declared caret ranges, or introduces a malicious transitive dependency through such a release. 3. A user follows `SKILL.md` and runs `npm install`. 4. Because no reviewed lockfile constrains versions and integrity hashes, npm resolves and installs the newly published package tree. 5. Malicious code exec ...[truncated 850 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
The render script lives in the **same skill folder** as this `SKILL.md`:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
the **directory containing this SKILL.md** as the skill path. The script is at `scripts/render.js` relative to that folder. Invoke: `node <skill_folder>/scripts

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
the **directory containing this SKILL.md** as the skill path. The script is at `scripts/render.js` relative to that folder. Invoke: `node <skill_folder>/scripts

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
the **directory containing this SKILL.md** as the skill path. The script is at `scripts/render.js` relative to that folder. Invoke: `node <skill_folder>/scripts

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
the **directory containing this SKILL.md** as the skill path. The script is at `scripts/render.js` relative to that folder. Invoke: `node <skill_folder>/scripts

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs agents to invoke this skill automatically whenever a reply would contain LaTeX, which is an overly broad trigger that can activate on many normal math or science interactions without explicit user intent. This increases the chance of unnecessary tool execution, expanded attack surface through untrusted LaTeX input flowing into the renderer, and policy/workflow violations where plain text would have been sufficient.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example guidance says to use tex-render automatically for scientific or math questions whenever a reply would contain LaTeX, which is ambiguous and encourages routine, implicit tool use. In practice this can cause excessive or unintended rendering operations on user-controlled content, making denial-of-service or misuse scenarios more likely even if the underlying libraries are legitimate.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill instructs the agent to invoke a local Node.js script and notes detectable environment/code capabilities, but it does not declare any explicit tool scope such as allowed tools or permissions. That omission weakens containment and reviewability, making it easier for an agent or runtime to execute beyond the minimum intended capability if the surrounding platform does not enforce stricter defaults.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to render and send images automatically without asking for permission. This delegates autonomous action to the agent, causing local script execution and file creation based solely on response content rather than explicit user approval, which can violate user expectations and increase operational risk.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
Renders LaTeX math to PNG, JPEG, WebP, or AVIF (and SVG). Use when you need a **viewable image** from LaTeX instead of raw code.

**User notice:** When this skill is active, the agent will **automatically** render any LaTeX in its replies as images and send them in order—without asking for permission. If you prefer to be prompted or to receive raw LaTeX instead, do not enable this skill (or remove it from your workspace).

## Location

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The TOOLS.md guidance tells the agent to use this skill whenever a reply would contain LaTeX, which is an overly broad automatic trigger. Broad triggers increase the chance of unnecessary code execution, unintended file generation, and misuse in contexts where rendering is not needed or where raw text would be safer and sufficient.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description says to invoke whenever the agent needs to output LaTeX as a viewable image, but it does not define specific trigger phrases, scope limits, or non-triggering cases. In a manifest-like description field, this can lead to ambiguous activation behavior across varied tasks.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified with a caret range, which allows newer minor/patch releases to be installed over time. This weakens build reproducibility and can silently introduce a compromised or vulnerable transitive release into a rendering skill that processes untrusted LaTeX input.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
"validate": "node scripts/validate.js"
  },
  "dependencies": {
    "@svg-fns/svg2img": "^0.2.0",
    "mathjax": "^4.1.0",
    "sharp": "^0.34.5"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The MathJax dependency is not pinned to an exact version, so installations may resolve to different releases over time. Because this skill renders attacker-controlled TeX input, version drift is more concerning: a newly introduced bug or a still-affected release could expose the renderer to denial-of-service or parsing-related issues.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
},
  "dependencies": {
    "@svg-fns/svg2img": "^0.2.0",
    "mathjax": "^4.1.0",
    "sharp": "^0.34.5"
  },
  "engines": {

Unverifiable Dependency: mathjax has 2 known advisory(ies) (CVE-2018-1999024 (Macro in MathJax running untrusted Javascript within a web browser); CVE-2023-39663 (MathJax Regular expression Denial of Service (ReDoS))), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest does not pin MathJax, while known advisories exist for the package family, including untrusted JavaScript execution in browser contexts and a ReDoS issue. In this skill's context, MathJax is central to processing untrusted TeX, so an affected resolved version could enable denial of service or other unsafe parsing behavior, and the lack of pinning makes the deployed risk unverifiable.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The sharp dependency is also version-ranged with a caret, allowing non-deterministic future installs. This matters here because image-processing libraries often have a history of memory-safety and codec-related issues, and this skill converts rendered output into image formats such as WebP and AVIF.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"dependencies": {
    "@svg-fns/svg2img": "^0.2.0",
    "mathjax": "^4.1.0",
    "sharp": "^0.34.5"
  },
  "engines": {
    "node": ">=14"

Unverifiable Dependency: sharp has 4 known advisory(ies) (GHSA-54xq-cgqr-rpm3 (sharp vulnerability in libwebp dependency CVE-2023-4863); GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); CVE-2022-29256 (sharp vulnerable to Command Injection in post-installation over build environmen) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The sharp package has multiple historical advisories, and the manifest's non-exact versioning means the installed version cannot be verified from this file alone. Since this skill performs image generation and format conversion using native/image codec dependencies, an affected release could expose the host to denial of service, memory corruption, or supply-chain risk during install or runtime.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline comment says DEFAULT_SCALE = 1 represents '3x resolution for sharper output on high-DPI displays', but the assigned value is 1, not 3 or any equivalent higher scale. This is an active contradiction between documentation and behavior, even though it is not security-significant by itself.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/validate.js:19