Back to skill

Security audit

Testing Patterns

Security checks for vulnerabilities and agentic risk

Overview

The testing guidance itself is coherent, but the README’s primary install command uses an unpinned executable installer and mutable GitHub source, which deserves review before use.

Review the install path before using it. Prefer a pinned commit, signed release, or manual installation from reviewed files instead of running the documented unpinned `npx add` command. The skill content itself is testing advice, but the installer command has broader local execution authority than the guidance requires.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:28
Finding

Unpinned Third-Party Package Execution in Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 28-32
Vulnerability Type: Unpinned package execution and mutable external source
Risk Level: Medium

Vulnerable Code

markdown
## Installation

```bash
npx add https://github.com/wpank/ai/tree/main/skills/testing/testing-patterns
text

### Technical Analysis

The installation command invokes `npx add`, causing npm to resolve and execute the third-party package named `add`. No exact package version, integrity hash, lockfile, or provenance requirement is specified. Consequently, the code executed by this command can differ between installations.

The argument also refers to content on the mutable Git branch `main`, rather than a reviewed commit SHA or immutable release artifact. Changes to that branch can therefore alter the installed content after this Skill has been audited.

There is no evidence that the current npm package or referenced repository is malicious. The vulnerability is the unsafe trust model: compromise of the npm package, its publisher account, the source repository, or the referenced branch could turn the documented installation command into a code-execution and supply-chain attack.

### Attack Path

1. An attacker compromises the npm package `add`, its publisher account, or an upstream dependency used by its command-line implementation. Alternatively, the attacker gains permission to modify the referenced repository's `main` branch.
2. The attacker publishes malicious package code or replaces the mutable repository content.
3. A user follows the README and runs the documented `npx add ...` command.
4. `npx` retrieves the package version available at execution time and runs its command-line or lifecycle code.
5. The malicious code executes with the privileges and environment of the installing user.
6. The code can access files, credentials, environment variables, and repositories available to that user, or modify the destin
...[truncated 824 chars]
Remediation
View remediation

Remediation Suggestions

  1. Avoid executing an implicitly resolved npm CLI package during installation. Prefer non-executable manual installation steps or a purpose-built installer maintained by the project.
  2. If an npm installer is required, pin it to an exact reviewed version rather than relying on the latest registry resolution.
  3. Verify the package's publisher, provenance, and integrity before execution. Use a lockfile or verified integrity digest wherever supported.
  4. Replace the mutable main reference with an immutable, reviewed commit SHA or signed release tag.
  5. Publish checksums or signatures for release artifacts and document how users should verify them before installation.
  6. Run installation tooling with least privilege in an isolated environment, without production credentials or unrelated repository access.
  7. Document the exact package being executed and explain why it is trusted, allowing users to review the installer before running it.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (7)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
|--------------|---------|-----|
| **Testing implementation** | Tests break on refactor, not on bugs | Test behavior and outputs, not internals |
| **Flaky tests** | Non-deterministic failures erode CI trust | Remove time/order/network dependencies |
| **Test pollution** | Shared mutable state leaks between tests | Reset state in `beforeEach` / `setUp` |
| **Sleeping in tests** | `sleep(2000)` is slow and unreliable | Use explicit waits, polling, or events |
| **Giant arrange** | 50 lines of setup obscure intent | Extract factories/builders/fixtures |
| **Assert-free tests** | Test runs but verifies nothing | Every test must assert or expect |

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 3)May include surrounding context.

md
# Testing Patterns

Unit, integration, and E2E testing patterns with framework-specific guidance. Write tests that catch bugs, not tests that pass — confidence through coverage, speed through isolation.

## What's Inside

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to install the skill via npx add from a GitHub URL without any pinning to a specific version, commit, or integrity value. That creates a supply-chain risk: the referenced content can change over time, so a later malicious or compromised update could be fetched and trusted implicitly by users following the documentation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

From your project root:

bash
mkdir -p .claude/skills
cp -r ~/.ai-skills/skills/testing/testing-patterns .claude/skills/testing-patterns

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 64)May include surrounding context.

Claude Code (global)

bash
mkdir -p ~/.claude/skills
cp -r ~/.ai-skills/skills/testing/testing-patterns ~/.claude/skills/testing-patterns

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: testing-patterns
model: standard
category: testing
description: Unit, integration, and E2E testing patterns with framework-specific guidance. Use when asked to "write tests", "add test coverage", "testing strategy", "test this function", "create test suite", "fix flaky tests", or "improve test quality".
version: 1.0

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description uses very broad trigger phrases such as 'write tests' and 'improve test quality', which can match many ordinary development requests and cause the skill to be invoked outside a narrowly intended scope. Over-broad auto-selection increases the chance that this skill influences unrelated tasks and expands the attack surface for prompt/skill routing abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.