T08 · Insecure Dependencies
- Location
references/target-codex.md:75- Finding
Unpinned npx Package May Download and Execute Untrusted Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent audit-and-port helper, but its bundled auditor can read outside the chosen source through symlinks and some validation guidance could execute mutable third-party code.
Install only if you are comfortable using it as a review tool on trusted or sandboxed source directories. For untrusted repositories, avoid running the bundled auditor until symlinks are rejected and file-size limits are enforced, pass --target-agent explicitly, and do not run the npx validation command unless the package source and version are pinned and reviewed.
references/target-codex.md:75Unpinned npx Package May Download and Execute Untrusted Code
scripts/audit_skill.py:160Target-Agent Inference Reads Every Environment Variable Value
scripts/audit_skill.py:579Auditor Follows File Symlinks Outside the Selected Source Directory
Referenced artifact was not completely inspected
- Prefer `scripts/audit_skill.py` for deterministic local inspection.
Referenced artifact was not completely inspected
- Prefer `scripts/audit_skill.py` for deterministic local inspection.
Referenced artifact was not completely inspected
- Prefer `scripts/audit_skill.py` for deterministic local inspection.
Referenced artifact was not completely inspected
- Prefer `scripts/audit_skill.py` for deterministic local inspection.
Referenced artifact was not completely inspected
- Prefer `scripts/audit_skill.py` for deterministic local inspection.
Referenced artifact was not completely inspected
- Prefer `scripts/audit_skill.py` for deterministic local inspection.
Referenced artifact was not completely inspected
- Portable: agent-neutral `SKILL.md`, references, examples, assets, templates.
Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.
| `.claude/agents/*.md` or `agents/*.md` | Convert procedural parts into skills. Keep role/runtime/subagent behavior as target-specific notes unless supported. |
| `.claude/settings*.json` hooks | Treat as unsupported lifecycle behavior unless the target has an equivalent hook mechanism. |
| `.claude-plugin/`, `plugin.json`, `manifest.json` | Inventory metadata. Convert plugin behavior into skills plus dependency notes. |
| `.mcp.json` or MCP server configs | Treat as dependency-bound. Capture server names, URLs, auth requirements, and credentials needed. |
| Managed Agent `agent.yaml` and callable agents | Treat as orchestration behavior. Port reusable instructions only; report subagent handoff requirements. |
| Cowork dispatch/project behavior | Treat as Claude/Cowork-specific unless the target environment provides a matching workflow. |
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| `.codex-plugin/plugin.json` | Convert into a target plugin/extension manifest only when target package fields are known; otherwise document as plugin implementation notes. |
| `.agents/plugins/marketplace.json` | Treat as distribution metadata. Do not assume another agent can consume it directly. |
| `.codex/agents/*.toml` or `~/.codex/agents/*.toml` | Convert required fields and instructions into target subagent format when supported; otherwise mark partial. |
| `.codex/config.toml`, `~/.codex/config.toml`, `[mcp_servers.*]` | Treat MCP/tool setup as dependency-bound. Convert simple configs only with target-specific review. |
| `.codex/hooks.json`, `hooks/hooks.json`, inline hooks in `config.toml` | Treat as risky lifecycle behavior. Convert only with known event/matcher/input/output mapping. |
## Codex-Specific Signals
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
| `agents/*.md` | Gemini subagents. Convert known fields to target subagent/custom-agent format; otherwise mark partial. |
| `hooks/hooks.json` | Gemini lifecycle hooks. Treat as risky lifecycle behavior requiring event/schema mapping. |
| `policies/*.toml` | Gemini policy rules/safety checkers. Treat as target-specific safety configuration, not as a skill. |
| `.gemini/settings.json`, `~/.gemini/settings.json`, `mcpServers` | MCP/tool setup. Treat credentials, trust, include/exclude tools, and scopes as dependency-bound. |
## Gemini-Specific Signals
Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.
- Convert Codex `AGENTS.md` and Gemini `GEMINI.md` into `CLAUDE.md` guidance or a bridge note.
- Convert Codex custom-agent TOML into Claude subagent Markdown only for known fields.
- Convert Gemini extension agents into Claude agent Markdown only for known fields.
- Keep MCP/provider setup as dependency notes unless the user explicitly asks to stage `.mcp.json`.
- Do not emit Claude dynamic context injection (`!` shell syntax) unless the source already used it and the command has been security reviewed.
- Do not enable hooks automatically.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
re.compile(rf"\.{lit('s', 's', 'h')}/"),
re.compile(rf"\.{lit('a', 'w', 's')}/"),
re.compile(rf"\.{lit('c', 'o', 'n', 'f', 'i', 'g')}/"),
re.compile(r"\bkeychain\b", re.IGNORECASE),
re.compile(r"\bprintenv\b"),
re.compile(r"\benv\s*>\b"),
],
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
if explicit:
return explicit, False
env_pairs = {key.upper(): value.lower() for key, value in os.environ.items()}
joined = " ".join(f"{key}={value}" for key, value in env_pairs.items())
if "CODEX" in env_pairs or "codex" in joined:
return "codex", True
The skill instructs the agent to inspect repositories, read references, potentially stage ported files, and document clone/fetch commands for remote sources, which implies meaningful file, shell, and possibly network use. Because it declares no explicit tool scope or allowed-tools boundary, a runtime may grant broader capabilities than intended, increasing the risk of unintended file modification, remote access, or command execution during analysis of untrusted skill/plugin content.
Enabling implicit invocation without trigger constraints allows this skill to be auto-selected in broader contexts than intended, which is risky because the skill can audit and stage ports of untrusted agent skills and plugins. In this context, unintended activation could cause the system to process adversarial repositories or generate follow-on actions based on unsafe inputs, increasing the chance of unsafe automation or trust boundary bypass.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Scope Heuristics
Choose a recommended scope without asking when the source structure is clear:
- **Single skill**: one `SKILL.md` and no plugin/command/agent/MCP structure.
- **Focused bundle**: multiple skills, commands, or integrations and no explicit request for all content.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- Single skill: `skills/claude/<skill-name>/`
- Multi-skill/plugin source: `ports/<source-name>/claude/`
- Do not write directly to `~/.claude/skills/` or `.claude/skills/` unless the user explicitly asks for installation.
## Target-Specific Package Surfaces
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- Single skill: `skills/codex/<skill-name>/`
- Multi-skill/plugin source: `ports/<source-name>/codex/`
- Do not write directly to `~/.codex/skills/` unless the user explicitly asks for installation.
## Claude-to-Codex Rules
The reference instructs running npx skills add . --list without pinning a package version or verifying provenance. npx can resolve and execute remote package code at runtime, so an unexpected package update, typo-squatted dependency, or registry compromise could lead to arbitrary code execution during validation.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
assets/ # optional templates or static assets
Gemini discovers skills from `.gemini/skills/`, `~/.gemini/skills/`, and the `.agents/skills/` alias. Keep `SKILL.md` frontmatter valid with `name` and `description`.
## Project Instructions
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- Single skill: `skills/gemini/<skill-name>/`
- Multi-skill/plugin source: `ports/<source-name>/gemini/`
- Do not write directly to `~/.gemini/skills/`, `.gemini/skills/`, or `.agents/skills/` unless the user explicitly asks for installation.
## Target-Specific Package Surfaces
The module-level security boundary says the script 'writes only when --output is explicitly provided'. However, the code supports a 'port' mode and constructs a porting map plus output_path values for staged translated artifacts, which contradicts the documented write boundary as written. Even if this file itself only emits a report, the documentation presents a stricter no-write guarantee than the behavior implied by the porting workflow it advertises.
The manifest describes a tool for auditing and porting skill repositories, but this file enumerates all environment variables and searches them to infer the target runtime. Reading the ambient environment is broader than necessary for repository auditing and may expose unrelated host context, while the target agent could be supplied explicitly or inferred from repository contents.
No suspicious patterns detected.