Back to skill

Security audit

Instapaper

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Instapaper CLI guide, with some credential-hygiene and supply-chain cautions users should handle before use.

Before installing, pin and verify the Instapaper CLI version where possible. Do not put a real password directly into copied shell commands; use an interactive prompt, a protected secret manager, or another method that avoids shell history and logs. Review destructive commands before running them, especially delete, folder delete, import, and bulk mutation operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/commands.md:10
Finding

Password May Be Disclosed Through Shell History and Command Logging

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- `references/commands.md`: command-by-command examples for auth, list/export/import, mutations, folders, highlights, and text.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example encourages supplying a password via a shell pipeline using a literal string. While --password-stdin is generally safer than passing a password directly as a command-line argument, this documented pattern still normalizes insecure credential handling in shell history, scripts, screenshots, and copied examples, and it provides no warning about secret hygiene. In an automation-focused CLI skill, users may reuse the pattern with real credentials in unsafe ways.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/commands.md (reported line 13)May include surrounding context.

md
- Login (stdin password):
  - `printf '%s' "pass" | ip auth login --username "you@example.com" --password-stdin`
  - Add `--no-input` to disable prompts.
- Check auth:
  - `ip auth status` or `ip --json auth status`
- Config:

Static analysis

No suspicious patterns detected.