Back to skill

Security audit

Safe Script Runner

Security checks for vulnerabilities and agentic risk

Overview

The skill is a narrow terminal workflow guide, with one supply-chain caution around an unpinned npx example but no hidden or malicious behavior.

Install only if you want an agent to prefer temporary script files over inline terminal snippets. For TypeScript tasks, prefer a project-local pinned tsx dependency or an already-installed binary instead of allowing `npx` to download packages on demand, and avoid loading full `.env` contents unless the task needs them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 22
Vulnerability Type: Supply-chain exposure through unpinned package execution
Risk Level: Medium

Code Snippet:

markdown
3. **Execute the File**: Run the file in the terminal using standard commands, such as `node temp_update_db.js` or `npx tsx temp_task.ts`.

Technical Analysis

The prescribed workflow permits execution of npx tsx without specifying a reviewed version, requiring a lockfile, verifying package integrity, or ensuring that only an already-installed local binary is used. If tsx is absent locally, npx may retrieve package content from the configured package registry and execute it.

This creates a dependency supply-chain boundary in which the code executed during a skill invocation may differ from the code reviewed with the skill. Exploitation would require control or compromise of a resolved package, one of its dependencies, the configured registry, or relevant package-resolution settings.

Attack Path

  1. An agent follows the mandatory workflow and creates a temporary TypeScript task.
  2. The project does not have a trusted, lockfile-pinned local tsx installation.
  3. The agent runs npx tsx temp_task.ts as recommended.
  4. npx resolves and potentially downloads tsx and its dependency tree from the configured registry.
  5. A compromised or malicious resolved package executes during installation or command startup.
  6. The package gains the same operating-system permissions and process environment available to the invoking agent.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the account running the agent. The resulting access is limited by that account's operating-system privileges but may include reading or modifying accessible project files, accessing available network resources, and reading environment variables exposed to the process. The document also requires temporar ...[truncated 230 chars]

Remediation
View remediation

Remediation Suggestions

  • Add tsx as an explicitly reviewed development dependency using an exact version and commit the package-manager lockfile.
  • Require lockfile-enforced installation, such as npm ci, in trusted build or setup workflows.
  • Replace implicit retrieval with execution of the pinned local binary, for example ./node_modules/.bin/tsx temp_task.ts, or use a package-manager command configured to reject remote installation.
  • If npx remains necessary, require a local-only or no-install mode so execution fails when the binary is unavailable rather than downloading code.
  • Apply dependency integrity checking, registry allowlisting, and automated supply-chain scanning.
  • Run temporary scripts with least privilege and expose only the environment variables required for the specific task.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs use of npx tsx without pinning a specific package version, which can cause execution of whatever version resolves at runtime from the registry or local environment. In an agent skill that normalizes running ad hoc scripts, this increases supply-chain risk because a compromised, newly published, or incompatible tsx release could be fetched and executed automatically.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.