Back to skill

Security audit

Find Skills (yuanfa版)

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to find and install other skills, but it gives agents broad triggers and recommends unpinned, global, confirmation-skipping installs of third-party content.

Review this skill carefully before installing. It can help discover skills, but its default workflow may run mutable remote npm tooling and install third-party skills globally without confirmation. Prefer explicit user approval, pinned CLI versions, reviewed publishers, immutable skill references, and local or isolated installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:88
Finding

Unpinned Third-Party CLI Execution and Unverified Global Skill Installation

Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` ```markdown ### Step 4: Offer to Install If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts. ``` ### Technical Analysis The skill instructs the agent to execute the `skills` npm package through `npx` without specifying an exact reviewed version. When an appropriate local package is unavailable, `npx` may download and execute the package currently published under that registry name. The project contains no lockfile, integrity hash, provenance requirement, or version constraint that would ensure the executed CLI is the same artifact that was previously reviewed. The CLI is subsequently used to install skills from “GitHub or other sources.” The documented workflow does not require source allowlisting, publisher verification, commit pinning, signature validation, dependency inspection, or review of the downloaded skill before activation. The installation command combines two risk-increasing options: - `-g` installs the selected skill globally at the user level, expanding its effect beyond the current project. - `-y` suppresses interactive confirmation, reducing the opportunity for the user to inspect ...[truncated 2176 chars]
Remediation
View remediation
find ``` Validate the precise package name and version before documenting this command. 2. Commit and verify package integrity information where the execution environment permits it. Require registry provenance, signatures, or cryptographic checksums for downloaded artifacts. 3. Restrict skill installation to an explicit allowlist of trusted publishers, repositories, and canonical HTTPS sources. 4. Pin installed skills to reviewed immutable commit hashes, release tags backed by verified signatures, or content digests rather than mutable branch names or search-result aliases. 5. Remove `-y` from the default workflow. Require explicit, informed user confirmation that displays: - The resolved publisher and repository. - The exact version or commit. - The installation destination. - Requested scripts and dependencies. - Whether the installation is global. 6. Avoid `-g` by default. Install skills into an isolated project-local directory or disposable sandbox with least privilege. 7. Download and inspect the complete skill package before activation. Review instruction files, scripts, lifecycle hooks, dependencies, symbolic links, and references to remote executable content. 8. Disable npm lifecycle scripts during acquisition when feasible, then enable only reviewed execution paths: ```bash npm install --ignore-scripts ``` 9. Run third-party discovery and installation tooling in a sandbox with restricted filesystem, credential, environment-variable, and network access. 10. Document an approval policy requiring users to authorize the exact resolved artifact rather than merely consenting to a broad package name or search result. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill should be used for broad prompts like 'how do I do X' or general interest in extending capabilities, which overlaps with many ordinary user requests. Over-broad activation can cause the agent to invoke a skill that searches for and installs external capabilities in contexts where the user only wanted advice, unnecessarily steering users toward unreviewed third-party code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to Use This Skill' conditions include ambiguous triggers such as asking 'can you do X' or expressing interest in extending capabilities, which are common conversational patterns. In this skill's context, false activations are more dangerous because they lead into a workflow that fetches and installs third-party tooling, increasing exposure to supply-chain and consent issues.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a specific package version, which means execution depends on whatever version is currently resolved from the registry at runtime. Because this skill is specifically about discovering and installing more third-party code, an upstream compromise, typo-squatted dependency, or breaking change could result in unreviewed code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using bare npx skills find [query] causes the CLI package to be fetched and executed without a fixed version. In a skill whose purpose is to search and later install external skills, this expands the trust boundary and creates a supply-chain execution risk if the package or one of its dependencies is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command example npx skills add <package> is not version-pinned, so the package manager and its transitive dependencies may vary over time. Since this command installs third-party skills from GitHub or other sources, the combination of unpinned bootstrap tooling and external package retrieval materially increases code-execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

npx skills check executes an unpinned package version, exposing users to unexpected code changes simply to check for updates. While less dangerous than installation, it still expands the attack surface through runtime execution of mutable remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

npx skills update invokes unpinned remote tooling to update installed skills, creating a compound supply-chain risk. An attacker controlling the resolved CLI version or influencing update behavior could cause arbitrary code or malicious skill updates to be installed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The instructions tell the agent to run npx skills find [query] as part of normal operation, again without pinning the CLI version. Because this is framed as an automated workflow step, users may execute it routinely without realizing they are trusting a mutable remote package each time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The example npx skills find react performance is an illustrative use of the same unpinned remote execution pattern. Even though it is sample text, users commonly copy-paste examples directly, so the security risk remains practical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The example npx skills find pr review repeats the same unsafe bootstrap pattern. In a discovery/install skill, these examples normalize executing mutable code from the network as a first step, which is poor security hygiene.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The example npx skills find changelog is another copy-pasteable invocation of an unpinned package. While individually low-complexity, repeated examples reinforce insecure behavior and increase the chance of unsafe execution by end users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The result text tells users to install with npx skills add <owner/repo@skill>, combining unpinned CLI execution with installation of third-party skill content. This encourages a chain of trust from an unpinned package manager to externally sourced code, which is particularly risky in an agent-extension ecosystem.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The installation example npx skills add <owner/repo@skill> -g -y is especially dangerous because it combines unpinned remote execution, global installation, and confirmation bypass. This can lead to silent system-wide installation of unreviewed third-party code, increasing persistence and blast radius if the CLI or target skill is malicious or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly recommends -g -y for installing third-party skills without warning about global scope, confirmation bypass, provenance review, or the risks of executing external code. This meaningfully lowers friction for unsafe installation and can result in persistent compromise or unintended capability changes with little user awareness.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The sample install command repeats the same unsafe pattern in a user-facing example. Because examples are likely to be executed verbatim, this continues to expose users to mutable remote code execution and external skill installation without sufficient safeguards.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

npx skills init is also an unpinned CLI invocation, so even the fallback guidance for creating a custom skill relies on executing mutable remote package code. While less severe than third-party skill installation, it still presents a supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The final example again recommends npx skills init my-xyz-skill without version pinning. Repetition across the document makes the insecure pattern systemic rather than incidental.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.