Back to skill

Security audit

Find Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate skill-discovery purpose, but it tells agents to run mutable external CLI code and globally install third-party skills while skipping confirmation.

Install only if you are comfortable with an agent searching for and installing third-party skills. Prefer reviewed sources, avoid `-y`, avoid global installation unless you need it, pin or verify the CLI and skill source where possible, and review any candidate skill before adding it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned Package Execution and Unverified Global Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:30-33, 49, 87-93
Vulnerability Type: Supply-chain exposure through mutable third-party packages
Risk Level: Medium

Vulnerable Code

bash
npx skills find [query]
npx skills add <package>
npx skills check
npx skills update
bash
npx skills find [query]
bash
npx skills add <owner/repo@skill> -g -y

The skill instructs the agent to execute npx skills without pinning the CLI package to a reviewed version. It also directs the agent to install skills identified through external search results, globally and without an interactive confirmation prompt.

Technical Analysis

An unqualified npx skills invocation may download and execute the package version currently resolved by the npm registry. Neither SKILL.md nor package.json pins a reviewed CLI version, records an integrity hash, or declares the CLI as a locked dependency.

The installation workflow additionally accepts an external <owner/repo@skill> identifier and uses -g -y. Global installation increases the affected scope, while -y suppresses the final confirmation opportunity. The documented process does not require repository allowlisting, commit pinning, source inspection, signature verification, or integrity validation before installation.

Consequently, the behavior reviewed during this audit may differ from the code ultimately downloaded and executed.

Attack Path

  1. An attacker publishes a malicious or confusingly named npm package, compromises the package resolved as skills, or compromises a subsequently resolved release.
  2. Alternatively, an attacker controls or compromises a skill repository surfaced by the external search service.
  3. A user requests skill discovery, causing the agent to follow the documented npx skills find workflow.
  4. npx retrieves and executes the mutable, unpinned CLI package under the agent or user account.
  5. The attacker-controlled result is selected for installatio ...[truncated 958 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an explicitly reviewed version, for example npx skills@&lt;reviewed-version&gt;, rather than resolving the latest available release.
  2. Prefer declaring the CLI in a lockfile-backed dependency set and executing the locally installed binary with immutable dependency resolution.
  3. Verify package provenance, signatures, and integrity metadata before execution.
  4. Pin installed skills to reviewed immutable commit hashes or signed releases rather than mutable repository references.
  5. Maintain an allowlist of trusted publishers and repositories.
  6. Download candidate skills into an isolated temporary directory and inspect their instructions, scripts, manifests, dependencies, and lifecycle hooks before installation.
  7. Run discovery and installation in a sandbox with minimal filesystem, credential, and network access.
  8. Remove -g as the default and install into a project-scoped or otherwise isolated location.
  9. Remove -y and require explicit, informed user approval after displaying the exact source, version or commit, requested scope, and review results.
  10. Document a rollback procedure for removing an installed skill and verifying that no unauthorized files or configuration remain.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough to match ordinary user requests like 'how do I do X' or general capability questions, which can cause the skill to activate in many benign conversations. In this skill's context, over-triggering is dangerous because activation leads toward searching for and potentially installing third-party skills, increasing unintended exposure to supply-chain and code-execution risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage guidance lists broad activation cues like asking 'can you do X' or expressing interest in extending capabilities, without clear boundaries or exclusions. That ambiguity can cause an agent to invoke this skill prematurely and steer users into third-party package discovery or installation when direct assistance would be safer.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill repeatedly instructs use of npx skills without pinning a version, which allows whatever package version is current at execution time to run. Because npx can fetch and execute remote code, a compromised upstream package, malicious update, or dependency hijack could lead to arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This command references npx skills without a fixed version, so the executed code is not stable or reviewable over time. In a skill whose purpose is to discover and install more extensions, this increases supply-chain risk because users may trust the automation and execute transient remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The documentation advertises npx skills add <package> without version pinning for the CLI itself, exposing users to execution of whatever package version resolves at runtime. Since this command also installs third-party skills, it compounds supply-chain exposure across both the CLI and installed content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx skills check without pinning means users rely on mutable remote package resolution even for routine maintenance actions. An attacker controlling or poisoning the package distribution path could execute arbitrary code during what appears to be a safe update check.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

npx skills update is especially risky when unpinned because it combines execution of mutable remote package code with update behavior that changes installed components. A malicious or compromised release could propagate harmful updates broadly and immediately.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The search step tells the agent to run npx skills find [query] without constraining the CLI version, creating a remote-code-execution path during ordinary discovery. Because this skill may trigger on broad help requests, users could be exposed without realizing a package fetch/execution is occurring.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The example command again uses unpinned npx skills, normalizing unsafe package execution patterns. Repetition throughout the document increases the chance that users and downstream agents will copy the insecure form directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This example search command executes a mutable remote package via npx, which is dangerous even though it appears read-only. In practice, npx package startup hooks and package code can perform arbitrary actions before any search logic runs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The changelog search example uses an unpinned CLI invocation, exposing users to arbitrary code execution from the package registry. Because examples are likely to be copied verbatim, this is an actionable unsafe instruction rather than a theoretical issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The installation instruction npx skills add <owner/repo@skill> again relies on an unpinned package manager CLI. In this context the danger is amplified because the command both executes mutable CLI code and installs additional third-party code from external repositories.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill offers to install a package using npx skills add <owner/repo@skill> -g -y, which combines unpinned remote package execution with global installation and skipped confirmations. This creates a strong path for silent persistence or broader system impact if the CLI or target skill is malicious or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly recommends -g -y installation of third-party skills without warning about global scope, skipped consent, or trust implications. This is dangerous because it encourages silent installation of externally sourced code with broader persistence and less user review, magnifying the impact of malicious or compromised skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The recommendation to run npx skills init without version pinning still exposes users to execution of mutable remote package code. Although initialization is lower risk than install/update, it remains an unnecessary supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The npx skills reference in the no-results guidance repeats the unsafe pattern of unpinned package execution. This keeps the document consistently vulnerable and makes secure usage less likely because every path models the same insecure behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This final npx skills init my-xyz-skill example is another instance of mutable remote code execution through npx. While not obviously malicious, repeated insecure examples across the skill materially increase exploitability through copy-paste adoption.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.