Back to skill

Security audit

flydb

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Flydb routing skill, with the main caution that its install examples fetch related skills from mutable remote sources.

Before installing the full skill family, verify the GitHub or SkillHub source, prefer a pinned commit or trusted release when available, and avoid installing or running migration-related skills in an environment that already has production database credentials unless you intend to grant that access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Skill Installation from a Mutable Remote Source

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31–38
Vulnerability Type: Unverified and unpinned third-party dependency installation
Risk Level: Medium

Evidence

bash
npx skills add https://github.com/zzxCoding/skills --skill flydb
npx skills add https://github.com/zzxCoding/skills --skill flydb-cli-release
npx skills add https://github.com/zzxCoding/skills --skill flydb-migration-scripts
npx skills add https://github.com/zzxCoding/skills --skill flydb-multi-environment

Technical Analysis

The documented installation procedure invokes an npx-resolved installer and retrieves Skills directly from a mutable GitHub repository. The repository reference is not pinned to an immutable commit, signed release, or verified artifact checksum. Consequently, the content installed by these commands can differ from the content that was originally reviewed.

This creates two supply-chain trust dependencies:

  1. The package and executable resolved by npx must remain trustworthy.
  2. The latest content served by the remote repository must remain trustworthy.

If either source, its publisher account, or its release process is compromised, the commands can install modified Skill instructions or related executable components without a local integrity check. This audit found no evidence that the current upstream content is malicious; the vulnerability is the unsafe, mutable installation mechanism.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or the package distribution path used by npx.
  2. The attacker modifies a child Skill or causes the installer to retrieve attacker-controlled content.
  3. A user or agent follows the installation commands in SKILL.md.
  4. The unverified content is written into the agent's Skills directory.
  5. When the installed Skill is subsequently loaded, its altered instructions or bundled components execute with the permissions ...[truncated 1123 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the remote repository to a reviewed, immutable commit hash instead of installing from its moving default branch.
  2. Pin the npx package to an exact reviewed version and avoid implicit installation of the latest release.
  3. Publish checksums or signed manifests for every child Skill and verify them before installation.
  4. Prefer vendoring reviewed child Skills with the parent package when licensing and maintenance requirements permit it.
  5. Add a mandatory review step that displays and inspects all downloaded Skill files before placing them in an active Skills directory.
  6. Perform installation in a restricted environment without production credentials, database access, or unnecessary filesystem permissions.
  7. Maintain an allowlist of approved repository commits and installer versions.
  8. Document rollback procedures so an altered or compromised Skill can be removed from every agent environment.
  9. Apply the same pinning and verification controls to the alternative SkillHub installation channel described later in SKILL.md; do not delegate installation to mutable remote instructions without integrity validation.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content throughout the skill forces a specific language/locale for all users, and there is no opt-in, alternative language option, or justification that this skill is intended only for a Chinese-speaking or region-specific audience. This can violate organizational language/locale policy for broadly distributed skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The skill instructs users to run npx skills add directly from a remote GitHub repository without pinning an exact package version, commit, or release. This creates a supply-chain risk: if the referenced package or its resolution path changes upstream, users may execute unexpected code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This line repeats an unpinned npx skills add installation flow for a different sub-skill, again relying on remote content that can change over time. In a skill installation context, that is especially sensitive because it influences what code or prompts get pulled into the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The command fetches and installs a sub-skill via unversioned npx, exposing users to upstream changes or repository compromise. Because the content becomes part of an agent skill set, successful exploitation could persist beyond a single command execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This installation instruction has the same supply-chain weakness as the other npx skills add examples: the runtime tool and fetched repository content are not pinned. An attacker who gains control of the package, dependency path, or referenced repo could deliver malicious skill content to users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON evaluation file encodes all user prompts, expected outputs, and assertions in Chinese, which effectively constrains the skill's behavior to a specific language. The file does not indicate that language choice is optional or that the skill is intentionally region-specific, so this appears to violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.