Back to skill

Security audit

Architecture Patterns

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent architecture-guidance skill, with a real supply-chain caution around its unpinned README install command and payment examples users should adapt carefully.

Prefer a pinned or manual installation path instead of the README's unpinned npx command. If you use the Stripe adapter template, treat it as sample backend code only and add explicit authorization, user confirmation where appropriate, logging, and environment-specific safeguards before connecting real payment credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:23
Finding

Unpinned Third-Party Installation Command Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: README.md:23-27
Vulnerability Type: Unpinned third-party installer and mutable remote source
Risk Level: Medium

Vulnerable Code

markdown
## Installation

```bash
npx add https://github.com/wpank/ai/tree/main/skills/backend/architecture-patterns
text

### Technical Analysis

The documented installation procedure invokes `npx` without pinning the `add` package to a reviewed version. It also references content under a mutable GitHub branch path rather than an immutable commit.

Consequently, the command may retrieve or execute components whose contents can change after this audit. If either the npm package resolution or upstream GitHub repository is compromised, users could receive code different from the reviewed project. This is a supply-chain weakness rather than evidence that the currently audited files are malicious.

### Attack Path

1. An attacker compromises the npm package resolved as `add`, its maintainer account, or the referenced GitHub repository.
2. The attacker publishes a malicious package release or modifies content on the mutable `main` branch.
3. A user follows the installation command from the README.
4. `npx` downloads and potentially executes the compromised package, while the installer retrieves mutable remote content.
5. Attacker-controlled code runs with the permissions of the user invoking the command.

### Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope may include access to files, environment variables, credentials, development repositories, and network resources available to that user. If the command is run by a privileged account or in a highly privileged CI environment, the impact expands accordingly.

No remote payload execution, credential theft, persistence, or other malicious behavior was observed in the currently audited project con
...[truncated 6 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package invoked by npx to an exact, reviewed version rather than allowing implicit latest-version resolution.
  2. Pin the GitHub source to an immutable commit SHA instead of the mutable main branch.
  3. Prefer downloading a release archive and verifying a published cryptographic checksum or signature before installation.
  4. Avoid executing package runners when simple, non-executable file-copy installation is sufficient.
  5. In CI environments, install with a minimally privileged account, restrict outbound network access, and use an approved dependency proxy or allowlist.
  6. Document the expected package version, source commit, and checksum so users can reproduce the audited installation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Creating a refund is a destructive financial action and also transmits payment identifiers and refund details to Stripe. This file contains no visible confirmation prompt, user disclosure, or warning that a refund request will be sent and may be irreversible or impactful.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

From your project root:

bash
mkdir -p .cursor/skills
cp -r ~/.ai-skills/skills/backend/architecture-patterns .cursor/skills/architecture-patterns

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 52)May include surrounding context.

From your project root:

bash
mkdir -p .claude/skills
cp -r ~/.ai-skills/skills/backend/architecture-patterns .claude/skills/architecture-patterns

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 59)May include surrounding context.

Claude Code (global)

bash
mkdir -p ~/.claude/skills
cp -r ~/.ai-skills/skills/backend/architecture-patterns ~/.claude/skills/architecture-patterns

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: architecture-patterns
model: reasoning
---

# Architecture Patterns

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code sends payment-related data, including payment method, amount, currency, order ID metadata, and description, to Stripe via a network call. Within this file there is no visible confirmation prompt, user-facing disclosure, or warning that external transmission of user/payment data occurs.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/clean-architecture-guide.md:387

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/hexagonal-architecture-guide.md:99