Back to skill

Security audit

Find Skills Tianjin

Security checks for vulnerabilities and agentic risk

Overview

This skill has a clear skill-discovery purpose, but it recommends broad activation and persistent global installs through unpinned commands that skip confirmations.

Review this skill before installing. Use it only when you explicitly want skill discovery, avoid the -g and -y install pattern by default, prefer pinned or reviewed CLI and skill versions, verify publishers and repositories, and avoid bulk updates without inspecting what will change.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Unpinned CLI Execution and Unsafeguarded Third-Party Skill Installation

Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` `SKILL.md:43-44`: ```bash npx skills find [query] ``` `SKILL.md:55-63`: ```text Install with npx skills add vercel-labs/agent-skills@vercel-react-best-practices └ https://skills.sh/vercel-labs/agent-skills/vercel-react-best-practices ``` `SKILL.md:79-84`: ```markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts. ``` ### Technical Analysis The skill directs an agent to invoke `npx skills` without pinning the npm package to a reviewed version or integrity value. Depending on the local npm environment, `npx` can retrieve and execute a package from the configured registry. Consequently, the effective CLI implementation may change after this skill has been audited. The workflow also permits skills to be installed from GitHub or unspecified other sources without requiring: - An allowlist of trusted publishers. - Immutable commit or release pinning. - Signature or integrity verification. - Inspection of the downloaded skill's instructions and scripts. - Review of package lifecycle behavior. - Explicit confirmation immediately before installation. The recommended installation command uses `-g`, extending the installation to the user's global skill environment, and `-y`, suppressing an intera ...[truncated 2634 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description uses broad trigger language such as helping when users ask 'how do I do X', which overlaps with many ordinary requests. This can cause the skill to activate in contexts where skill discovery is unnecessary, increasing the chance of unsolicited package search or installation guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation guidance is ambiguous and expansive, covering generic questions like 'can you do X' or expressions of interest in help for a domain. In this context, overbroad activation is risky because the skill promotes third-party package discovery and installation workflows that may not be necessary for the user's goal.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning an exact package version. Because npx resolves and executes packages dynamically, a compromised upstream package, typo-squatted dependency, or unexpected breaking update could lead to execution of unreviewed code in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Referencing npx skills without a pinned version causes the agent or user to fetch and run whatever version is current at execution time. This creates a supply-chain risk window where malicious or unsafe changes upstream could be executed automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command example uses npx skills without constraining the package version, so execution depends on mutable remote state. An attacker who compromises the package or its dependencies could achieve arbitrary code execution when the command is run.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx skills unpinned for update-related operations increases risk because it may retrieve a modified CLI and then perform broader package changes. This amplifies supply-chain exposure by combining execution of a mutable tool with package management actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The unpinned npx skills command leaves the executed code path dependent on the latest published package contents. In a skill whose purpose is discovery and installation, this is especially dangerous because it normalizes running remote code as part of routine use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The search instruction tells users to run npx skills find [query] without pinning a version, exposing them to arbitrary upstream changes at the moment of execution. Even a search command is risky because the package itself must first be downloaded and executed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This example output includes installation guidance centered on the same unpinned npx skills workflow, reinforcing unsafe package execution practices. While illustrative, it still conditions users toward running mutable remote package manager commands without safeguards.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The example install command relies on npx skills without an exact version, so users may execute a different CLI than the one originally documented. Because this command installs additional code, compromise or drift in the CLI could directly impact the host environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill offers to install packages using an unpinned npx skills add command. This is a direct remote code execution pathway: both the CLI and the installed skill may change over time, making the behavior non-deterministic and potentially malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends npx skills add <owner/repo@skill> -g -y, which both installs globally and suppresses confirmation prompts without warning about the risks of third-party code execution. This materially lowers user visibility and consent, making accidental or unsafe installation more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Suggesting npx skills init without pinning still instructs users to execute a mutable remote package. Although initialization is less immediately dangerous than global install, it still requires running code fetched at execution time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This additional npx skills reference continues the same unsafe pattern of unpinned remote execution. Repetition increases the chance that users and agents normalize insecure invocation of package-management commands.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.