Back to skill

Security audit

10x Patterns

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only development-practices skill with disclosed install instructions and no hidden execution behavior, though its mutable npx/GitHub install paths deserve caution.

Review and pin the installer source before installing if you need strong supply-chain assurance. Prefer a reviewed version or commit hash, avoid running npx installers with elevated privileges, and choose per-project installation unless you intentionally want the skill active globally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Package Execution via ClawHub Installer

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: Medium

Vulnerable Code:

bash
npx clawhub@latest install 10x-patterns

Technical Analysis

The installation instructions invoke clawhub through npx using the mutable latest tag. An npx invocation can download and execute npm package code, including package entry points and lifecycle scripts, with the privileges of the current user.

Because latest does not identify an immutable, reviewed release, the code executed by this command can change after the Skill itself has been audited. Compromise of the package, publisher account, npm distribution channel, or a future malicious release could therefore turn this documented installation command into an arbitrary code-execution path.

The repository does not include or constrain the remotely resolved package and does not provide a version pin, integrity hash, or signature that would allow users to verify the downloaded artifact.

Attack Path

  1. An attacker compromises the clawhub package, its publisher account, or the relevant package-distribution process.
  2. The attacker publishes a malicious release and assigns or causes it to receive the latest tag.
  3. A user follows the documented installation command.
  4. npx resolves and downloads the attacker-controlled package version.
  5. Package or lifecycle code executes in the user's environment.
  6. The malicious code can perform actions available to the invoking user.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The accessible scope may include source repositories, user-readable files, development credentials, environment variables, SSH configuration, package-manager tokens, and any services reachable with the user's existing permissions.

This command does not itself request ...[truncated 361 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with a specific, reviewed package version.
  • Where supported, verify the package against a published integrity hash or cryptographic signature.
  • Use a lockfile or equivalent mechanism to preserve the reviewed dependency resolution.
  • Document the expected package publisher, version, checksum, and provenance.
  • Prefer an installation process that downloads content for inspection before executing it.
  • Re-audit the pinned artifact whenever the version is updated.
  • Avoid running the installer with administrative privileges and use an isolated environment where practical.

T08 · Insecure Dependencies

Warning
Location
README.md:28
Finding

Mutable npm and GitHub Sources Used by Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md:28-34
Vulnerability Type: Unpinned npm execution and mutable repository source
Risk Level: Medium

Vulnerable Code:

bash
npx add https://github.com/wpank/ai/tree/main/skills/meta/10x-patterns
bash
npx clawhub@latest install 10x-patterns

Technical Analysis

Both documented installation alternatives depend on mutable remote content.

The first command executes an unversioned npm package named add through npx and supplies a GitHub path on the mutable main branch. Consequently, both the installer package selected by npm and the repository content referenced by the command may change after review. The use of a generic package name also makes package identity and provenance less clear to users.

The second command executes clawhub through the mutable latest npm tag. Neither command specifies an immutable npm version, Git commit hash, integrity digest, or signature. If any resolved package, publisher account, or repository is compromised, installation may execute or install content that differs from the audited Skill.

Attack Path

  1. An attacker compromises the npm package or publisher account used by either npx command, or gains write access to the referenced GitHub repository.
  2. The attacker publishes malicious package code, changes the package tag, or modifies content on the main branch.
  3. A user copies one of the installation commands from the README.
  4. npx resolves the mutable package and remote repository content at execution time.
  5. Attacker-controlled package logic or installed Skill content is processed in the user's environment.
  6. Malicious installer code can act immediately, while malicious Skill content could affect later Agent sessions when loaded.

Impact Assessment

Compromise of executable npm content could result in arbitrary code execution with the invoking user's privileges. Potentially expos ...[truncated 573 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the add and clawhub npm packages to explicit, reviewed versions.
  • Replace the mutable GitHub main reference with a full, reviewed commit hash or signed release tag.
  • Publish expected checksums or signatures and require verification before installation.
  • Clarify the exact package identity and trusted publisher instead of relying on an ambiguous generic invocation.
  • Provide a non-executing manual installation option that downloads the artifact for review before copying it into an Agent configuration directory.
  • Use lockfiles or a verified release manifest where applicable.
  • Run installation in a least-privileged, isolated environment and never require administrative privileges.
  • Re-audit all pinned remote artifacts before updating their versions or commit references.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (9)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to execute remote package tooling via npx add against a GitHub URL without any version pinning or integrity control. This creates a supply-chain risk: if the referenced package, installer behavior, or remote content changes, users may execute unintended code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx clawhub@latest install 10x-patterns pulls and executes the latest published package version at install time, which is mutable and could change unexpectedly or maliciously. This exposes users to supply-chain compromise if the package is hijacked, a bad release is published, or dependencies are poisoned.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 43)May include surrounding context.

From your project root:

bash
mkdir -p .cursor/skills
cp -r ~/.ai-skills/skills/meta/10x-patterns .cursor/skills/10x-patterns

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 59)May include surrounding context.

From your project root:

bash
mkdir -p .claude/skills
cp -r ~/.ai-skills/skills/meta/10x-patterns .claude/skills/10x-patterns

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 66)May include surrounding context.

Claude Code (global)

bash
mkdir -p ~/.claude/skills
cp -r ~/.ai-skills/skills/meta/10x-patterns ~/.claude/skills/10x-patterns

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: 10x-patterns
model: standard
description: Patterns and practices that dramatically accelerate development velocity. Covers parallel execution, automation, feedback loops, workflow optimization, and anti-pattern avoidance. Use when starting projects, planning sprints, optimizing workflows, or onboarding developers.
---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use the skill when 'starting projects, planning sprints, optimizing workflows, or onboarding developers,' which are broad, everyday development activities rather than narrowly scoped trigger phrases. This can cause unintended invocation because the file does not define specific trigger boundaries, exclusions, or negative examples.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The installation command uses npx clawhub@latest, which fetches and executes the newest package version at runtime rather than a pinned, reviewed release. That creates a supply-chain risk: a compromised upstream package or malicious newly published version could execute arbitrary code on the user's machine during installation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
| Shared component libraries | Reusable, tested UI building blocks | Consistent UI, no re-implementation |
| Preview deployments | Every PR gets a live URL (Vercel, Netlify) | Instant stakeholder feedback |
| Trunk-based development | Short-lived branches, frequent merges to main | Eliminates merge hell |
| Continuous deployment | Every merge to main auto-deploys | Zero manual deploy overhead |
| Database migrations as code | Version-controlled, repeatable schema changes | No manual DB modifications |
| Infrastructure as code | Terraform, Pulumi, SST for infra | Reproducible environments in minutes |
| API-first design | Define API contracts before implementation | Frontend and backend work in parallel |

Static analysis

No suspicious patterns detected.