Back to skill

Security audit

Next Upgrade

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Next.js upgrade helper, but it will run codemods and update project dependencies when used.

Install this only when you want an agent to make dependency and source-code changes for a Next.js upgrade. Run it on a clean branch, review the exact npm package versions and codemod command before execution, and inspect all generated diffs before accepting them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:24
Finding

Unpinned Third-Party Packages Are Downloaded and Executed

Content
View full analysis
``` ```bash npm install next@latest react@latest react-dom@latest ``` ```bash npm install @types/react@latest @types/react-dom@latest ``` ### Technical Analysis The skill directs the agent to resolve third-party packages through the mutable `@latest` distribution tag. In particular, `npx @next/codemod@latest` may download and immediately execute package code with the permissions of the agent process. The installation commands also resolve mutable package versions without requiring exact version pinning, lockfile enforcement, integrity verification, package review, or explicit user approval. Package behavior can consequently change after the skill has been reviewed. A compromised package publisher account, registry response, or newly published package version could introduce attacker-controlled code. Package installation may also invoke package lifecycle scripts. ### Attack Path 1. An attacker compromises a relevant package release channel, publisher account, or mutable `latest` tag. 2. The attacker publishes a malicious version or causes the mutable tag to resolve to attacker-controlled package content. 3. An agent follows the skill and invokes the specified `npx` or `npm install` command. 4. The package is retrieved without an exact reviewed version being enforced. 5. The codemod or applicable installation lifecycle code executes with the permissions and environment available to the agent process. 6. The malicious code can access or alter resources available to that process, including project files and any exposed credentials. ### Impact Assessment Successful exploitation could result in arbitrary code execution under the agent process's privileges. The attacker could read or modify the target ...[truncated 428 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs use of npx @next/codemod@latest, which executes remote package code at the latest unpublished state rather than a reviewed, pinned version. In an agentic workflow this is especially risky because the command directly runs third-party code with developer privileges, creating supply-chain exposure if the package is compromised or a breaking/malicious release is published.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill tells the agent to run dependency-changing commands such as npm install next@latest react@latest react-dom@latest without warning that they will modify package.json and the lockfile. In practice this can cause unintended repository changes, surprise upgrades, and harder-to-review diffs, which is risky for automated agents even though it is not overtly malicious.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.