Back to skill

Security audit

PinMe Deploy

Security checks for vulnerabilities and agentic risk

Overview

This deployment skill matches its IPFS publishing purpose, but it asks the agent to run project build commands and upload content publicly without enough safeguards or warnings.

Review the build output before upload, use this only on projects you trust, inspect package.json scripts before allowing npm commands, and use scoped Pinata credentials. Assume uploaded files may be public and difficult to remove from IPFS gateways.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:83
Finding

Unsafe Installation and Execution of Untrusted Project Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 83–84
Vulnerability Type: Untrusted dependency lifecycle and project-script execution
Risk Level: High

Complete Code Snippet:

bash
npm install
npm run build

Technical Analysis

The skill instructs the agent to run npm install and npm run build automatically when a framework project has no existing build directory.

npm install can execute lifecycle scripts supplied by dependencies, including preinstall, install, and postinstall. The instruction does not require a trusted lockfile, dependency-source validation, lifecycle-script suppression, or review of dependency changes. Consequently, a malicious package introduced through a compromised dependency, dependency confusion, typosquatting, or an attacker-controlled project can execute code during installation.

In addition, npm run build executes the target repository's package-defined build command. An attacker controlling package.json can replace the expected frontend build operation with arbitrary shell commands. No sandboxing, command review, least-privilege restriction, or explicit user confirmation is required before execution.

Attack Path

  1. An attacker supplies or modifies a frontend project containing either:
    • a dependency with a malicious installation lifecycle script; or
    • a malicious build entry in package.json.
  2. The user invokes the deployment skill for that project.
  3. The skill detects package.json and the absence of a prebuilt dist/ or build/ directory.
  4. Following the documented workflow, the agent executes npm install.
  5. The package manager runs attacker-controlled dependency lifecycle code, if present.
  6. The agent then executes npm run build, which can invoke an attacker-controlled shell command.
  7. The malicious process runs with the privileges and accessible environment of the agent process.

Impact Assessment

...[truncated 699 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit user approval before installing dependencies or executing project-defined scripts.
  2. Inspect and display the relevant package.json scripts before running them.
  3. Require a committed lockfile and use the corresponding deterministic installer, such as:
    bash
    npm ci --ignore-scripts
    
  4. Validate dependency registry sources and reject unexpected Git URLs, local paths, untrusted registries, and lockfile inconsistencies.
  5. Audit dependencies before allowing lifecycle scripts. Enable only specifically reviewed scripts when they are essential.
  6. Execute installation and build operations in an ephemeral, unprivileged container or sandbox with:
    • read-only access to source files where possible;
    • a dedicated writable build-output directory;
    • no host credential directories;
    • restricted network access;
    • resource and execution-time limits.
  7. Remove PINATA_API_KEY, PINATA_SECRET_KEY, and other deployment secrets from the build environment. Inject them only into the separate upload step after the build completes successfully.
  8. Review produced artifacts before upload and ensure the build process cannot modify files outside its isolated workspace.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill encourages deployment to IPFS/Pinata but does not clearly warn that uploaded content becomes public and is sent to a third-party service. Users may unintentionally publish sensitive files, configuration data, or internal assets to a permanent or hard-to-retract distribution channel.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document lists '提供部署统计和访问监控' and '支持增量更新' as built-in features, but the described workflow only covers local project inspection, optional npm build, and a single Pinata upload via curl. No code/documented commands implement monitoring, stats collection beyond an example output, or differential upload logic, so the feature claims materially overstate what the skill actually does.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The options section claims '--watch' will monitor file changes and redeploy and '--open' will automatically open a browser, but the rest of the file provides no commands or logic for file watching, local server startup, or launching a browser. This is more than incomplete documentation because the documented CLI behaviors contradict the only concrete implementation shown.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Documenting automatic execution of 'npm install' and 'npm run build' without warning is dangerous because package lifecycle scripts and build scripts can execute arbitrary code from an untrusted project. In the context of a deployment skill operating on user-supplied directories, this materially increases the risk of local code execution, credential theft, or filesystem/network abuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill explicitly transmits files and API credentials to an external service (Pinata). In this skill's context, external transmission is expected functionality, but it is still security-relevant because it sends potentially sensitive project contents off-host and to a third party; without strong warnings and scope controls, users may unintentionally exfiltrate data.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

使用 Bash 工具执行部署脚本:

bash
curl -X POST https://api.pinata.cloud/pinning/pinFileToIPFS \
  -H "pinata_api_key: YOUR_API_KEY" \
  -H "pinata_secret_api_key: YOUR_SECRET_KEY" \
  -F "file=@<build_dir>/index.html"

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The '高级功能' section presents '--ens', '--team-share', and later '--gateway' as supported commands, but no deployment flow, API call, or script logic shows how these options are handled. Since the file presents these as operative commands rather than future ideas, the documentation diverges from the actual behavior described elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs users to place API keys in environment variables without any caution about secret handling. While environment variables are common, omission of handling guidance can lead to accidental disclosure through shell history, shared terminals, screenshots, logs, or inherited subprocess environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.