Back to skill

Security audit

Web Slides

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it declares an unnecessary unpinned global npm install that can run code during installation.

Review or remove the global npm dependency before installing. If you use the preview renderer, render only HTML produced by the skill or otherwise trusted content, and choose output paths carefully because the scripts create or overwrite files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned and Unused Global npm Dependency Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:11
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

yaml
dependencies: "npm install -g @aspect-ratio/preview-renderer"

Technical Analysis

The Skill metadata instructs users or the hosting framework to install @aspect-ratio/preview-renderer globally without specifying an exact version, lockfile, or integrity hash. This resolves a mutable package release from the npm registry at installation time.

npm packages can execute lifecycle scripts during installation. Consequently, compromise of the named package, its publication credentials, or a future release could cause arbitrary code to execute with the privileges of the account installing the Skill.

The audited project does not import or invoke this package. Preview rendering is implemented directly through headless Chrome in scripts/chrome-utils.mjs and scripts/render-preview.mjs. The global dependency therefore creates supply-chain exposure without supporting the reviewed execution path.

Attack Path

  1. An attacker compromises the npm package, its maintainer account, or a future release.
  2. The attacker publishes a malicious version containing npm lifecycle code.
  3. A user or Agent installs the Skill and executes the declared command:
    sh
    npm install -g @aspect-ratio/preview-renderer
    
  4. npm retrieves the mutable package version and runs its applicable lifecycle scripts.
  5. The malicious code executes under the installing user's privileges and can access resources available to that account.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user performing the installation. Depending on that account's permissions, the malicious package could read or modify user-accessible files, environment variables, project data, and globally installed Node.js components.

...[truncated 193 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the dependency declaration because no audited script uses @aspect-ratio/preview-renderer.
  2. If the package becomes necessary, install it locally rather than globally.
  3. Pin an exact reviewed version instead of resolving the latest release.
  4. Commit and enforce a lockfile with integrity metadata.
  5. Verify package ownership, provenance, publication history, and source repository before adoption.
  6. Review the package and transitive dependencies for lifecycle scripts.
  7. Disable npm lifecycle scripts where operationally feasible, then explicitly run only required build steps.
  8. Execute installation and rendering in a restricted environment with minimal filesystem, network, credential, and environment-variable access.
  9. Add automated dependency scanning and controlled update review before accepting future versions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (22)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
主 `SKILL.md` 只保留路由和生成规则。需要细节时按需读取:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is primarily in Chinese and does not indicate that language output will adapt to the user's preference. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The operational instructions are entirely in Chinese, and there is no note that the skill should match the user's preferred language or that it is intentionally limited to Chinese-speaking users. This creates a language-policy concern because the skill appears to impose a language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly states '输出单文件 HTML 演示文稿', which imposes Chinese-language output behavior without indicating that it should follow the user's requested language. In an agent skill, hardcoding output language can override user intent, degrade reliability, and be abused as instruction steering that causes incorrect or non-compliant responses in multilingual contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L005 uses an imperative instruction in Chinese that sets the rule for how the skill should behave, but the file does not indicate that Chinese is optional or limited to a justified region-specific context. This creates a natural-language locale policy concern because it implicitly forces a specific language without offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all substantive guidance in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. That can violate the language/locale policy because it implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's user-facing natural-language content is entirely in Chinese, including headings and behavioral description, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage instructions are written entirely in Chinese and direct behavior in that language, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy requirements when a skill imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing descriptive content exclusively in Chinese, but it does not indicate that the skill is region-specific or provide any opt-in for language preference. Under the policy rule, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This function launches a Chrome subprocess via execFileSync and writes a screenshot to the caller-supplied outputPath, but the file contains no confirmation prompt, logging, or explanatory comments warning that it will execute an external binary and create a file. Because these are safety-relevant side effects, the lack of disclosure makes the behavior less transparent to users and integrators.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated document sets <html lang="zh-CN"> unconditionally, which enforces a specific language/locale regardless of user preference. SQP-3 covers language or locale policy violations when a skill forces a locale without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file contains user-facing instructional text in Chinese, which can impose a language/locale requirement on users without opt-in. The policy allows fixed-language behavior only when a language choice is offered or the locale restriction is clearly justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains all substantive guidance in Chinese, but it does not indicate that the user opted into that language or that the file is intended only for a Chinese-language audience. Per the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing descriptive content in Chinese throughout the substantive sections, but it does not indicate that the language is optional or limited to a specific locale-specific use case. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file uses Chinese throughout its descriptive content, which effectively forces a specific language for users without any opt-in or alternative. The policy explicitly calls for flagging language or locale constraints when the skill does not offer user choice or justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's descriptive guidance is written entirely in Chinese, which imposes a specific language/locale on users without offering a choice or documenting that the theme is intended for a Chinese-only audience. The policy explicitly calls for flagging language or locale constraints when they are forced without opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill content is written entirely in Chinese and provides no indication that language choice is optional or that the theme is intended only for a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s instructional content is written entirely in Chinese, which imposes a specific language/locale on users without indicating any choice, opt-in, or region-specific justification. Under the policy for natural-language violations, a forced language can be a finding when the constraint is not explicitly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's descriptive content is written in Chinese, while headings remain in English, and there is no indication that the skill is intentionally region-specific or that users can opt into the language/locale. Under the policy criteria, forcing a specific language without user choice or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated document sets <html lang="zh-CN">, which forces a specific language/locale in the output. Under the policy, locale-specific behavior should either be optional for the user or clearly justified as region-specific; neither is indicated in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs a filesystem write to a caller-controlled output path and creates parent directories, but there is no confirmation prompt, warning comment, or user-facing notice before the write occurs. For this code file, SQP-2 applies to safety-relevant file writes when they lack any form of disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated page sets lang="zh-CN", which imposes a specific language/locale on all output. The file also includes Chinese-only descriptive text later in the template, but there is no indication that this gallery is intentionally region-specific or that users can opt into this locale.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/build-preview-gallery.mjs:28

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/chrome-utils.mjs:27

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/generate-theme-gallery.mjs:34

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/smoke-test.mjs:13