Back to skill

Security audit

Microsoft Code Reference

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Microsoft documentation helper with an optional command-line fallback that should be used cautiously because it installs or runs an unpinned npm package.

Prefer the Microsoft Learn MCP tools when available. If you use the CLI fallback, avoid running it with elevated privileges, consider pinning a reviewed `@microsoft/learn-cli` version, and avoid the global install unless you intentionally want a persistent command-line tool.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:81
Finding

Unpinned npm Package Execution and Global Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 81-86
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

sh
# Run directly (no install needed)
npx @microsoft/learn-cli search "BlobClient UploadAsync Azure.Storage.Blobs"

# Or install globally, then run
npm install -g @microsoft/learn-cli
mslearn search "BlobClient UploadAsync Azure.Storage.Blobs"

Technical Analysis

The documented fallback commands resolve @microsoft/learn-cli without specifying an exact version or verifying package integrity. Consequently, npm retrieves whichever release the registry currently identifies as the applicable latest version.

The npx command can download and immediately execute package code. The alternative global installation persists the package in the user's global npm environment and may run npm lifecycle scripts during installation. Although the package name and publisher scope are consistent with the skill's stated purpose, the instructions do not protect against a compromised publisher account, malicious or defective future release, or npm registry supply-chain compromise.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or the associated release process.
  2. The attacker publishes a malicious version under the legitimate @microsoft/learn-cli package name.
  3. A user follows the fallback instructions in SKILL.md.
  4. Because no exact version or integrity value is specified, npm retrieves the attacker-controlled release.
  5. npx immediately runs the package, or npm install -g installs it globally and may execute lifecycle scripts.
  6. The malicious package executes with the privileges of the invoking user and can access resources available to that account.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the invoking user's account. Depending on that account's ...[truncated 592 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an exact, reviewed version, for example:
    sh
    npx @microsoft/learn-cli@X.Y.Z search "BlobClient UploadAsync Azure.Storage.Blobs"
    
  2. Verify the selected release's provenance and integrity before recommending it. Where practical, document the expected npm integrity hash or use a lockfile in a controlled wrapper project.
  3. Disable npm lifecycle scripts with --ignore-scripts if the CLI functions correctly without them:
    sh
    npx --ignore-scripts @microsoft/learn-cli@X.Y.Z search "BlobClient UploadAsync Azure.Storage.Blobs"
    
  4. Remove the global installation recommendation. Prefer an ephemeral, pinned invocation or a locally installed dependency governed by a committed lockfile.
  5. Prefer the Microsoft Learn MCP endpoint described by the skill when it is available, reducing the need to download and execute a local npm package.
  6. Advise users to run the CLI without elevated privileges and in an environment that does not expose unrelated credentials or sensitive files.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill recommends executing npx @microsoft/learn-cli without pinning a specific package version. That causes the latest package from the registry to be fetched and executed at runtime, which creates a supply-chain risk if a malicious or compromised release is published or if behavior changes unexpectedly. In this skill context, the command is presented as a direct fallback workflow, so users may run it verbatim, increasing exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.