Back to skill

Security audit

find-skills-in-tencent-skillhub

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Skillhub management wrapper, but it can install or upgrade agent skills and the Skillhub CLI through mutable, unverified external sources.

Review the Skillhub CLI source and installation instructions before installing. Use check_only before upgrades, avoid force unless you intend to replace an existing skill directory, and treat self-upgrade or upgrade-all as trust-changing operations because they can alter future agent behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Mutable and Unverified External CLI Installation Source

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-14
Vulnerability Type: Unverified third-party dependency installation instructions
Risk Level: Medium

Vulnerable Code Snippet:

markdown
### Install skillhub CLI

Follow [skillhub.md](https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md) to install Skillhub CLI.

Technical Analysis

The skill directs users or agents to retrieve installation instructions from a mutable object hosted in an external Tencent COS bucket. The repository does not contain the referenced instructions, pin the CLI to an immutable release, or specify a cryptographic checksum or signature for the downloaded software.

Consequently, the effective installation procedure can change after this skill has been audited. If the hosting account, bucket, object, DNS resolution, or publication process is compromised, the remote document could be replaced with instructions that download and execute attacker-controlled software. This is a supply-chain trust issue; the repository itself does not demonstrate that the remote content is currently malicious.

Attack Path

  1. An attacker compromises or gains unauthorized publishing access to the external storage location or its release process.
  2. The attacker replaces skillhub.md with modified installation instructions that retrieve or execute an attacker-controlled binary or script.
  3. A user or agent follows the prerequisite documented in SKILL.md.
  4. The malicious installation command executes with the privileges of the invoking user.
  5. The installed program may then abuse its intended skill installation and self-upgrade capabilities to introduce additional untrusted components.

Impact Assessment

Successful exploitation can provide arbitrary code execution with the privileges of the user performing the installation. This may permit access to files, credentials, agent configuration, and skill ...[truncated 384 chars]

Remediation
View remediation

Remediation Suggestions

  1. Store the reviewed installation procedure directly in the repository so it is covered by source review and version control.
  2. Pin the CLI to a specific immutable release version rather than retrieving mutable installation instructions.
  3. Download release artifacts only from an authenticated, trusted release channel.
  4. Publish and verify a SHA-256 checksum or cryptographic signature before executing or installing any downloaded artifact.
  5. Fail closed when integrity verification fails; do not permit an unchecked fallback download.
  6. Require explicit user approval before installation or self-upgrade operations.
  7. Disable automatic self-upgrades by default, or ensure updates use the same version pinning and signature-verification controls.
  8. Document the expected artifact URL, version, signer identity, checksum, and installation destination to make future audits reproducible.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill advertises self-upgrade and notes automatic self-upgrade checks on startup, but it does not include a clear caution about modifying the CLI installation or contacting remote services for update checks. In markdown skill descriptions, upgrade and network-affecting behavior should be disclosed when they can affect system integrity or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes file-affecting behavior such as installing skills and a force option that overwrites an existing directory, but it does not provide an explicit user warning about local filesystem changes. For markdown files, SQP-2 applies when potentially impactful behavior affecting user data or system state is described without warning.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
## Install Options

- `slug`: Skill identifier to install (required)
- `force`: Overwrite existing directory (default: false)
- `files_base_uri`: Base URI for local archives
- `download_url_template`: Custom download URL template

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The self-upgrade action invokes skillhub self-upgrade, which can modify the local toolchain or installed binaries without any explicit runtime confirmation, dry-run-by-default behavior, or warning to the caller beyond the usage text. In an agent context, this is risky because a higher-level workflow or prompt injection could trigger environment-changing behavior unexpectedly, potentially altering future execution trust boundaries or introducing unreviewed code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The install and upgrade paths execute package-management style operations (skillhub install and skillhub upgrade) that can change the local environment without an additional runtime disclosure or confirmation gate. Although shell injection is handled well through argument arrays and basic validation, the core risk remains that an agent may be induced to install or upgrade code unexpectedly, which is especially relevant for a skill-discovery/management tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.