Back to skill

Security audit

Content Generation

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a content-writing guide, but it asks to install an unexplained unpinned npm package and expose a search API key.

Review the package install before using this skill. It should either remove axios or pin and justify it, and it should explain exactly how BRAVE_API_KEY and command-line tools are used for research. The skill does not appear malicious, but the install and environment requirements deserve manual review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned npm Dependency Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11-15
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code:

yaml
    install:
      - id: npm
        kind: node
        package: axios
        bins: ["axios"]

Technical Analysis

The Skill requests installation of the npm package axios without specifying an exact version, lockfile, or integrity hash. Consequently, installation may resolve to mutable package-registry state rather than a dependency version reviewed during the audit.

If the package, one of its transitive dependencies, or the relevant registry account is compromised, a malicious release could introduce attacker-controlled code. Depending on package-manager configuration, lifecycle scripts may execute during installation. The declared axios executable is also not justified by the documented content-generation behavior, increasing the supply-chain attack surface without a demonstrated functional requirement.

Attack Path

  1. An attacker compromises the npm package publication process, a maintainer account, the package registry, or a transitive dependency.
  2. The attacker publishes a malicious version that satisfies the unrestricted dependency declaration.
  3. A user installs or deploys the Skill after the malicious release becomes available.
  4. The package manager resolves and downloads the attacker-controlled release.
  5. Malicious lifecycle code may execute during installation, or malicious library behavior may execute when the dependency is used.
  6. The payload operates with the permissions of the account or environment performing the installation.

Impact Assessment

Successful exploitation could allow code execution with installer-level privileges. Depending on the deployment environment, the attacker could access files, environment variables, API credentials, network resources, and other data available to the installing ...[truncated 212 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove axios if it is not required by any implemented Skill behavior.
  2. If it is required, pin it to a reviewed exact version rather than using an unrestricted package declaration.
  3. Use a committed lockfile and verify package integrity through trusted checksums or registry integrity metadata.
  4. Review and pin all transitive dependencies where the installation system supports it.
  5. Disable npm lifecycle scripts during installation when they are unnecessary, for example by using an equivalent of --ignore-scripts.
  6. Install dependencies in a sandboxed, non-privileged environment with minimal filesystem, credential, and network access.
  7. Document why the dependency and any declared executable are necessary for content generation.
  8. Add automated dependency scanning and controlled update review before accepting new versions.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises a very broad, generic content-generation capability with catch-all triggers such as creating 'any written content' and generic quick actions. In agent environments that auto-select or suggest skills from descriptions, this can cause over-invocation, accidental routing of unrelated tasks, or use in contexts lacking sufficient policy or domain constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.