Back to skill

Security audit

CloudCreate Tools

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a CloudCreate.ai link guide, but it tells agents to run mutable npm code and includes an unrestricted watermark-removal route.

Install only if you are comfortable with a skill that may guide agents to CloudCreate.ai and may run the CloudCreate npm CLI. Prefer manually constructed URLs or a pinned, reviewed CLI version, avoid running `npx --yes` in sensitive workspaces, and treat the watermark-removal feature as sensitive and only use it for content you are authorized to modify.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:26
Finding

Execution of Unpinned Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-35
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
# Print a production URL.
npx --yes @cloudcreate/cli open image:resize --mode width --width 1200 --quality 82 --format webp --locale en --print

# Open the production browser tool directly.
npx --yes @cloudcreate/cli open css:minify --level aggressive --locale zh

# Print a self-hosted/local URL.
npx --yes @cloudcreate/cli open image:compress --quality 75 --format webp --base-url http://127.0.0.1:5173 --locale en --print

Technical Analysis

The documented commands invoke npx --yes with an unpinned npm package name. If the package is absent locally, npm can download and execute the version currently resolved from the configured registry. The --yes option suppresses the normal installation confirmation.

Because no audited version, integrity value, or trusted registry configuration is specified, the effective code executed can change after the skill has been reviewed. A malicious package release, compromised maintainer account, registry compromise, or compromised transitive dependency could therefore cause arbitrary package or lifecycle code to execute.

The local deployment guidance at SKILL.md:65-70 also recommends cloning an external repository and running npm install without requiring a pinned repository commit or verified dependency lockfile, expanding the same supply-chain exposure.

Attack Path

  1. An attacker compromises @cloudcreate/cli, one of its transitive dependencies, its publishing account, or the package distribution channel.
  2. The attacker publishes a malicious version that remains compatible with the unversioned package reference.
  3. A user or agent follows the skill and runs npx --yes @cloudcreate/cli ....
  4. npm resolves and downloads the attacker-controlled release without interactive installa ...[truncated 1020 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specifically reviewed version, for example:
    bash
    npx @cloudcreate/cli@<reviewed-version> open ...
    
  2. Remove --yes where practical so that package installation requires explicit user approval.
  3. Verify package provenance, publisher identity, signatures or attestations, and registry source before execution.
  4. For repeatable or automated use, declare the package in a controlled project manifest, commit the lockfile, and install with npm ci.
  5. Run the CLI with least privilege in a sandbox or container that does not expose unrelated credentials or sensitive files.
  6. Pin the locally cloned application to an audited commit or signed release rather than an unspecified repository head.
  7. Require the repository's reviewed lockfile and use npm ci instead of an unconstrained npm install.
  8. Document expected package versions and integrity metadata so users can detect unexpected supply-chain changes.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation rule says to apply the skill not only when the user names CloudCreate.ai, but also whenever the request 'fits these tools.' That broad routing can cause the agent to steer generic user requests toward this product, overriding user intent and increasing exposure to the skill's riskier capabilities and external links.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs the agent to invoke npx --yes @cloudcreate/cli without pinning an exact package version. That allows whatever version is current in the registry at execution time to run, creating a supply-chain risk if the package is updated maliciously or incompatibly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This is another unpinned npx --yes @cloudcreate/cli invocation. Because npx may fetch and execute code from the package registry on demand, the skill creates a path for unintended code execution through a mutable external dependency.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The local/self-hosted example still relies on npx --yes @cloudcreate/cli without a version pin, so the same registry-sourced execution risk applies even when the destination URL is localhost. The dangerous part is the fetched CLI code, not the base URL it opens.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly catalogs and quick-maps a watermark-removal route: Remove the standard visible Gemini corner mark (local). Even though framed as a tool-routing entry, it operationally enables content provenance stripping, which can facilitate deceptive reuse of generated media and bypass of attribution or platform markings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction says to prefer the conversation language and, if unclear, 'ask or default to en'. Defaulting to a specific language without user choice can violate language/locale policy expectations, especially when the skill supports both English and Chinese.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.