Back to skill

Security audit

atifact

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for converting agent session logs, but users should treat both the inputs and generated outputs as sensitive.

Install the CLI only from a trusted npm package source, consider pinning or reviewing the package version, and process HAR/session logs in a controlled directory. Review and redact generated trajectory JSON before sharing it because it may preserve prompts, responses, tool outputs, headers, metadata, or other confidential session content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18–22
Vulnerability Type: Supply-chain risk from an unpinned global dependency
Risk Level: Medium

Vulnerable Code:

markdown
If not installed, install globally:

```bash
npm install -g atifact
text

### Technical Analysis

The skill instructs users to install `atifact` globally from the npm registry without specifying a reviewed version or package integrity value. Consequently, the installed package is whichever release the registry resolves at execution time, and its contents may differ from those present when the skill was audited.

npm packages may execute lifecycle scripts during installation with the invoking user's privileges. A compromised publisher account, malicious new release, or registry-level supply-chain incident could therefore cause arbitrary code to run during installation. Global installation also places the CLI in a broadly accessible executable location, increasing the scope and duration of the affected tool installation.

The project provides no lockfile, checksum, vendored implementation, publisher verification procedure, or source-review requirement to establish the installed artifact's provenance and integrity.

### Attack Path

1. An attacker compromises the package publisher, publishing pipeline, or another relevant supply-chain component.
2. The attacker publishes a malicious `atifact` release containing a harmful lifecycle script or altered CLI implementation.
3. A user follows the skill's instruction and runs `npm install -g atifact`.
4. npm resolves the unpinned package to the malicious release.
5. A lifecycle script may execute immediately with the user's privileges, or the malicious behavior may execute when the CLI is subsequently invoked.
6. The compromised CLI can access files and resources available to that user, including the HAR or JSONL session logs supplied for conversion.

### Impact Assessment

S
...[truncated 677 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin atifact to a specifically reviewed version rather than resolving the latest release:
    bash
    npm install --global atifact@<reviewed-version>
    
  2. Prefer a project-local dependency recorded in package.json and locked with package-lock.json; install it reproducibly with npm ci.
  3. Verify the package's registry, publisher, source repository, signatures or provenance attestations, and integrity metadata before installation.
  4. Review the package and its transitive dependencies for lifecycle scripts. Use --ignore-scripts where compatible with the package's legitimate installation requirements.
  5. Run the converter in a restricted environment with access only to required input and output paths, particularly when processing sensitive session records.
  6. Document the expected package version and a controlled upgrade-review procedure so dependency updates do not silently change the audited behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill instructs users to convert HAR files and agent session logs into trajectory JSON without warning that those inputs often contain sensitive prompts, conversation history, tool outputs, API metadata, and sometimes credentials or tokens. The generated trajectory files can persist this sensitive data in new locations or stdout, increasing the chance of accidental disclosure, improper sharing, or ingestion into less-protected systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.