Back to skill

Security audit

jest-unittest

Security checks for vulnerabilities and agentic risk

Overview

This Jest testing skill has a coherent purpose, but its scripts can run injected shell commands or delete unintended directories if given a crafted component name.

Review before installing. This skill should only be used in trusted repositories with trusted component names and a locked local Jest installation; it should be fixed to validate component names, enforce path containment, avoid shell command strings, and disable implicit npx installs before normal use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
sub-skills/unittest-checker/scripts/analyze-coverage/index.cjs:42
Finding

Shell Command Injection Through Unvalidated Component Names

Content
View full analysis
&1`, { cwd: projectRoot, encoding: 'utf-8', shell: true, maxBuffer: 50 * 1024 * 1024, }); } ``` The Skill instructions als ...[truncated 1946 chars]
Remediation
View remediation
&1`. Capture `stdout` and `stderr` through process API options. 5. Update the Skill instructions so `$ARGUMENTS` and `$PATH` are never directly interpolated into Bash commands. 6. Add regression tests covering semicolons, spaces, command substitution, pipes, redirections, traversal tokens, control characters, and leading dashes. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
sub-skills/unittest-checker/scripts/analyze-coverage/index.cjs:49
Finding

Arbitrary Recursive Directory Deletion Through Component-Name Path Traversal

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/reload.cjs:43
Finding

Shell Injection and Out-of-Project File Access Through jestConfigPath

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/guard-config.cjs:61
Finding

Unpinned npx Invocation Can Retrieve and Execute Undeclared Jest Code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (29)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- `config.json` — 由 `reload.cjs` 自动生成的完整配置

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
- `config.json` — 由 `reload.cjs` 自动生成的完整配置

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
- `config.json` — 由 `reload.cjs` 自动生成的完整配置

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- `config.json` — 由 `reload.cjs` 自动生成的完整配置

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README presents all user-facing instructions in Chinese and does not indicate that the skill supports other languages or that Chinese is a documented, justified locale requirement. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are very broad and include many common testing-related terms, which can cause the skill to activate in conversations that only casually mention tests or coverage. Over-broad invocation increases the chance of unintended execution paths, unnecessary file/script operations, and user confusion about why the agent is taking testing actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description and operating instructions are entirely in Chinese, and there is no indication that users may interact in another language or opt into this locale. Under the stated policy, a language constraint should either be optional or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The script invokes npx jest --version without pinning a package version or ensuring it resolves only to a trusted local dependency. In some environments, npx may fetch or resolve an unexpected package/version, which can lead to execution of untrusted code during what is intended to be a safety check.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file-level documentation says this script parses Jest configuration, validates key fields, and generates config.json for other scripts. However, it also invokes npx jest --version via child_process.execSync, introducing subprocess execution capability that is not implied by simple config parsing or JSON generation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames the skill as focused on unit-test checking, completion, and repair. This module automatically migrates configuration files and deletes the old copies (unlinkSync), which is operational state management not reflected in the manifest's user-facing description of testing capabilities.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a unit-testing skill set for checking coverage, completing tests, and diagnosing test failures. This helper executes an external shell command (git rev-parse --show-toplevel) via execSync, which introduces subprocess execution capability that is not clearly justified by the stated testing-only purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The migration routine automatically copies legacy config files to a new location and then deletes the originals without any user notice, confirmation, rollback, or integrity check. If the new write is incomplete, incorrect, or unexpected in a multi-process or interrupted run, users can silently lose configuration state or experience confusing breakage, making this a real integrity and availability risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructions and user-facing behavior are entirely specified in Chinese, with no indication that the user may choose another language or that the skill is restricted to a Chinese-speaking context. This creates a natural-language locale policy concern because it implicitly enforces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script takes the user-controlled --name argument, substitutes it directly into config.testOneCommand, and passes the resulting string to execSync, which invokes a shell. If an attacker can supply a crafted component name containing shell metacharacters, they may execute arbitrary commands in the project context. In a testing skill that is expected to run developer tooling automatically, this is especially dangerous because command execution is a normal part of the workflow and may occur without additional review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该技能的触发词包含“写单测”“自动写测试”“提升覆盖率”等较宽泛、常见的开发表达,容易在用户只是讨论测试思路、查看错误或进行普通代码问答时被误触发。一旦触发,技能具备 Bash、Write、Edit 等高权限工具,并会自动运行脚本、修改测试文件、循环迭代到 100% 覆盖率,因此误触发会放大为不必要的代码执行和文件改写风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script takes a user-controlled component name from argv and interpolates it into a shell command via config.testOneCommand.replace(...), then executes it with execSync. Because execSync invokes a shell for string commands, a crafted component name can inject additional shell syntax and execute arbitrary commands on the host running the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description uses broad natural-language phrases such as test failure, debugging, and repair requests without clear scoping constraints, which can cause the skill to activate on loosely related user input. Because this skill is allowed to run Bash and edit files, accidental activation can lead to unintended test execution or code modification in situations where the user did not actually request those actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

文件整体以中文直接规定技能任务和交互流程,但没有说明可根据用户语言偏好切换,也未提供语言/locale 选择。这构成自然语言层面的语言策略约束,可能在未获用户同意时强制特定语言。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script builds a shell command from configuration plus the user-controlled --name argument and executes it with execSync(..., shell: true). If specificName contains shell metacharacters, an attacker can inject arbitrary commands, causing code execution in the project root during a test run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The --name parameter is user-supplied and is inserted directly into config.testOneCommand before shell execution, with no validation, escaping, or confirmation. In this skill context, the agent may pass through user-provided component names automatically, which increases the chance of command injection and unintended command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file states that the AI will automatically guide configuration on first use, and later explains that it auto-creates source.json and generates or overwrites config.json. Because these are file-write behaviors affecting the user's workspace, the skill description should clearly warn users up front that local files under .temp/ will be created or regenerated.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/guard-config.cjs:63

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/reload.cjs:169

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/resolve-project.cjs:30

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
sub-skills/unittest-checker/scripts/analyze-coverage/index.cjs:63

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
sub-skills/unittest-completer/scripts/check-coverage-100/index.cjs:47

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
sub-skills/unittest-doctor/scripts/test-error-reporter/index.cjs:39