Back to skill

Security audit

Printing Press Library

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned, but it normalizes mutable third-party code execution that can install or overwrite local CLIs and agent skills.

Review before installing. The skill is not deceptive, but it asks your agent to run mutable package-manager commands that can change local executables and future agent skills. Use it only when you trust the Printing Press Library supply chain, prefer pinned or reviewed versions where possible, and require explicit approval before installs, overwrites, bulk updates, or any scheduled update job.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:61
Finding

Unpinned Third-Party Code Installation and Updates

Content
View full analysis
`. - In OpenClaw, use `npx -y @mvanhorn/printing-press-library install --agent openclaw` so the focused skill is materialized under OpenClaw's managed skills root; the installer defaults the Go binary into a per-user bin directory. - The install command installs both the CLI and the matching focused agent skill. - `install ` is idempotent: re-running it on an already-installed tool refreshes the Go binary and overwrites/re-adds the focused skill in place. - Behind the scenes, the installer uses `go install @latest` for the CLI and the Vercel Agent Skills-compatible `skills` CLI to install the focused `pp-*` skill globally from this repo. ``` The same unsafe installation pattern is further documented at lines 130–135: ```bash npx -y skills@latest add mvanhorn/printing-press-library/cli-skills/pp- -g -y ``` ```markdown The install operation is idempotent and works as a reinstall for one tool. Re-running `install ` uses `go install @latest` for the binary and re-adds the focused skill non-interactively, overwriting the existing install in place. No uninstall-first step is needed. ``` ### Technical Analysis The skill instructs the agent to execute third-party npm packages using `npx -y`, install the latest Go module version using `go install @latest`, and invoke `skills@latest`. These commands do not pin reviewed versions or require integrity verification. The effective code retrieved by these commands can therefore change after the skill itself has been audited. The `-y` flags suppress interactive confirmation, while the global skill installation and overwrite behavior allow newly retrieved content to replace existing agent instru ...[truncated 1983 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
ClawHub renders `SKILL.md` (or `skill.md`) as the skill readme. A separate `README.md` in the skill folder is not the published readme. Put user-facing ClawHub

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description is broad enough to trigger on many generic requests for tools, APIs, scrapers, or automation. In an agent ecosystem, overbroad activation is dangerous because it can steer ordinary tasks toward third-party package installation and code execution when safer built-in tools may suffice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The main usage instruction says to use the skill whenever a user asks for a CLI, agent skill, API wrapper, scraper, automation tool, or data source, which is an expansive trigger. That ambiguity increases the chance of unnecessary external tool discovery and installation, widening exposure to supply-chain and over-permission risks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill repeatedly instructs the agent to execute npx -y @mvanhorn/printing-press-library without pinning an exact package version. This allows the fetched code to change over time and creates a supply-chain risk where a compromised publisher account, dependency, or newly released malicious version could be executed immediately by the agent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This command uses npx to fetch and execute an unpinned package version at runtime. Because the package version is not fixed, the behavior can drift or become malicious later, turning routine search operations into remote code execution through the npm supply chain.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill recommends running an unpinned npm package via npx, which implicitly trusts the latest published version each time. In an agent context, that is especially dangerous because it normalizes autonomous execution of mutable third-party code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install primitive is unpinned and therefore executes whatever package version is current at invocation time. Since install flows have elevated impact and can materialize new tools and skills, compromise here can lead to persistence and broader agent capability expansion.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This variant of the install command for OpenClaw still relies on an unpinned package fetched with npx. Because it targets agent skill installation, exploitation could plant or overwrite skills in a managed skills root and affect future sessions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
7. Offer an efficient periodic update schedule after successful install or refresh.
   - Because install/update is idempotent, it is safe to keep installed Printing Press CLIs and focused skills current with a scheduled job.
   - Do not create a cron/scheduled job without explicit user approval; recurring jobs are durable side effects.
   - Avoid one scheduled job per CLI as the default. Users may install many Printing Press tools, and per-tool jobs become noisy and hard to manage.
   - Prefer one consolidated recurring job that runs `npx -y @mvanhorn/printing-press-library update`, which refreshes every installed Printing Press CLI currently on PATH and its matching focused skill.
   - Offer a per-tool job using `npx -y @mvanhorn/printing-press-library update <slug>` only when the user explicitly wants a different cadence or policy for that one tool.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documented canonical install command remains unpinned, preserving the same supply-chain risk. Even though this is instructional text, agent skills are often followed literally, so unsafe examples materially increase exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The OpenClaw example installs both binaries and focused skills through a mutable package reference. In context, this is more dangerous than a simple CLI example because it can change agent behavior across restarts and profiles.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This installation example fetches and runs the latest npm package version, which is inherently mutable. Because the skill frames this as the canonical interface, it encourages broad adoption of an unsafe execution pattern.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command installs a tool and focused agent skill using an unpinned runtime package, creating a direct path for supply-chain compromise to become persistent agent-state modification. The context increases severity because the command is presented as normal operational guidance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill describes invoking npx -y skills@latest add ..., which explicitly tracks the latest version of a secondary installer. Chaining two mutable package executions magnifies supply-chain risk and could allow compromise of the installer used to add global skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The update command is also unpinned, so routine maintenance can unexpectedly execute newly published code. Since update flows are likely to be automated later, this increases exposure over time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This general update command executes an unpinned package and is especially risky because it is intended to refresh multiple installed tools at once. If compromised, one invocation can affect many local components and skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Even version-check or metadata lookup commands become a code-execution vector when performed through unpinned npx packages. The danger is lower than install, but still real because the agent executes remote code just to query state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This list operation still relies on unpinned runtime package execution. Attackers can exploit low-suspicion read-only workflows because users are less likely to scrutinize them, yet the same remote code execution surface exists.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This update example includes a bin directory but still executes a mutable package reference. An attacker controlling the package could abuse the trust of an update flow to replace binaries or alter installation paths.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The paired update example on the same line is also unpinned and can overwrite local binaries based on mutable remote package behavior. This raises the blast radius beyond mere querying and makes persistence more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The example install command remains unpinned and therefore trusts future unpublished changes. Because examples often get copy-pasted directly into automated agent runs, the risk is operational rather than purely theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The weekly consolidated update recommendation uses an unpinned package, making scheduled maintenance a recurring remote-code-execution opportunity. Automation amplifies risk because compromise can occur later without renewed human scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This per-tool scheduled update example is likewise unpinned. Although narrower in scope, it still creates a durable execution path for mutable third-party code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The reinstall alias example executes the same unpinned package and therefore inherits the same supply-chain risk. Users may see aliases as convenience operations and lower their guard, which does not reduce exploitability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The Hermes install-and-reload section again recommends an unpinned install command. Because this context explicitly discusses making new skills visible to the running agent, successful exploitation can directly alter future agent capabilities.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.