Back to skill

Security audit

find-skills

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent but pushes broad skill discovery and global third-party skill installation through mutable unpinned commands, so users should review before installing.

Install only if you are comfortable letting this skill guide an agent to search for and install other skills. Before running any suggested command, prefer a verified or pinned CLI version, inspect the target skill source and revision, avoid `-g` unless you need global availability, and do not use `-y` when you want a confirmation checkpoint.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:26
Finding

Unpinned Third-Party CLI Execution and Unattended Global Skill Installation

Content
View full analysis
]` - Search for skills interactively or by keyword, optionally scoped to a GitHub owner - `npx skills add ` - Install a skill from GitHub or other sources - `npx skills update` - Update all installed skills ``` Lines 88–94: ```markdown ### Step 6: Offer to Install If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` ``` ### Technical Analysis The skill instructs the agent to execute `npx skills` without pinning the CLI to a reviewed version or verifying its package integrity. By default, `npx` can resolve and execute a package from the npm registry if a suitable local copy is unavailable. Consequently, the code executed at audit time may differ from the code executed later. The installation instructions also accept GitHub packages or unspecified “other sources.” No requirement is imposed to pin skills to immutable commit hashes, verify signatures or checksums, inspect downloaded files, or constrain sources to an allowlist. The recommended installation command compounds this exposure: - `-g` installs the selected skill globally at the user level, increasing its reach across projects and future sessions. - `-y` suppresses confirmation prompts, reducing the opportunity to inspect the package, source, version, and requested changes. - The package reference is not pinned to an immutable revision. - Install counts, repository stars, and publisher reputation—although mentioned elsewhere in the document—do not provide code-integrity guarantees and cannot prevent repository compromise, malicious updates, dependency confusion, or account takeover. This is a supply-chain w ...[truncated 1979 chars]
Remediation
View remediation
skills`. - Use a lockfile and integrity metadata where the execution environment supports them. - Review every version update before changing the pin. 2. **Pin skills to immutable revisions** - Require an exact release artifact or Git commit SHA rather than a mutable branch, tag, or unversioned package reference. - Record the expected checksum or signature and verify it before installation. 3. **Restrict installation sources** - Establish an explicit allowlist of approved registries, GitHub organizations, repositories, and package owners. - Remove support for unspecified “other sources” unless they undergo equivalent verification. - Protect against lookalike names and typosquatting by validating the exact owner and repository identity. 4. **Review content before installation** - Download the candidate into an isolated temporary directory without executing it. - Inspect skill instructions, scripts, lifecycle hooks, dependencies, and configuration changes. - Scan the artifact for secrets, obfuscated code, external payload retrieval, destructive commands, and persistence mechanisms. 5. **Avoid unattended global installation** - Remove `-y` so the package identity, revision, source, and changes can be confirmed. - Avoid `-g` by default; prefer project-local or sandboxed installation with narrowly scoped permissions. - Require explicit, informed user authorization immediately before installation. 6. **Isolate execution** - Perform discovery and installation in a container or restricted environment without production credentials, SSH keys, sensitive environment variables, or broad filesystem access. - Deny network and filesystem access not required for the installation. 7. **Secure update behavior** - Do not use an ...[truncated 177 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description activates on broad phrases like 'how do I do X' and generalized capability requests, which overlap heavily with normal assistant behavior. That can cause the skill to trigger too often and steer routine conversations into package discovery and installation workflows, increasing the likelihood of unnecessary execution of external tooling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to Use This Skill' section contains ambiguous triggers like asking 'can you do X' or wishing for help in a domain, without guardrails or exclusions. In this context, ambiguity matters because the skill leads to external package search and possible installation, so over-activation can become a pathway to unsafe recommendations or command execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a specific package version. npx may fetch and execute the latest published package at runtime, so a compromised upstream package, dependency, or malicious update could lead to arbitrary code execution on the user's machine during search, install, or update flows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command references npx skills without version pinning, which allows execution of whatever version is current at invocation time. In a skill whose purpose is to help discover and install more code, that creates a software supply-chain risk and increases exposure to malicious or compromised package releases.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Using npx skills add <package> without pinning the skills CLI version means the agent may execute an unexpected upstream release. Because this path leads directly to installing additional packages from external sources, compromise of the CLI or its resolution path could cascade into arbitrary code execution and further untrusted installs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The unpinned npx skills update example can execute a newly published CLI version and then update all installed skills, multiplying blast radius if the package or update channel is compromised. This is especially risky because it combines remote code execution with broad modification of the local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This search command again uses npx skills without an exact version, exposing users to execution of a mutable upstream package. Even though it is framed as discovery, the act of invoking npx is itself code execution and should be treated as sensitive.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The example npx skills find react performance is unpinned and therefore non-deterministic. A future malicious or compromised release could change behavior and execute unintended code while appearing to perform a harmless search.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command example invokes the skills package through npx without version pinning, creating a supply-chain execution risk. Since the skill is designed to steer users toward installing external functionality, this makes the overall workflow more dangerous than a standalone documentation example would be.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The unpinned npx skills find changelog example executes a mutable package from the network. Attackers who compromise the package or dependency chain could exploit user trust in the skill documentation to gain code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The install example encourages use of npx skills add ... without pinning the CLI version. Because this command installs additional skill code from external sources, the context substantially increases risk: both the package manager and the target package may be untrusted or mutable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill offers to install with -g -y but does not warn that this performs a global installation and suppresses confirmation prompts. In a skill that brokers third-party code installation, omitting that warning can lead users to authorize broad local-environment changes without understanding scope or having a chance to review what will be installed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

npx skills add <owner/repo@skill> -g -y is especially risky because it combines unpinned runtime package execution with global installation and prompt suppression. That creates a low-friction path for silent system-wide changes if the CLI or referenced skill source is malicious or compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx skills init is unpinned and therefore executes a mutable package from the registry. While lower risk than install/update flows, it still exposes users to arbitrary code execution through supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This additional unpinned npx skills invocation contributes to a repeated pattern of executing mutable remote code. Repetition across the skill increases the chance an agent will automatically follow the guidance, amplifying supply-chain exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.