Test fixture · version-bound review

snyk-labs/toxicskills-goof

UnratedCoverage incomplete
Test fixtureReview 21 reviewed finding1 unresolved
Assessment Not rated Coverage incomplete
Primary finding Demo instructions invoke mutable or remote bootstrap code
Severity medium
Confidence high
Findings 1 reviewed · 1 unresolved

Analyst conclusion

snyk-labs/toxicskills-goof is a security demonstration repository, so many alarming scanner matches are examples rather than evidence of active malicious behavior. The material issue in the reviewed commit is its setup path: mutable mcp-scan@latest execution and a curl-to-shell installer cause code selected outside the pinned repository snapshot to execute locally. If the resolved package, download endpoint or delivered bytes change unexpectedly or are compromised, that code runs with the authority of the invoking user or agent and can potentially reach local files, credentials and project data available to that process. Two remote-pipe strings in the bundled Snyk skill remain unresolved because the retained machine evidence proves the command text but does not establish enough surrounding behavior to determine whether those commands are reachable intended instructions or demonstration material. The Audit remains unrated because 21 inventory entries were skipped, nine surfaces were skipped or reduced, and one file had an extraction error.

Reviewed sourcesnyk-labs/toxicskills-goof·80ce2e06f52fd384163c4bd6778676019723773c

Why

The README tells the operator to invoke mcp-scan through a mutable @latest package reference and separately documents a curl-to-shell bootstrap command for OpenCode. In either case, code selected or downloaded at execution time crosses from remote package or web infrastructure into local execution without the reviewed repository snapshot itself pinning the executed bytes.

Potential harm

The remotely selected code executes with the authority of the invoking user or agent. If the upstream artifact is compromised or changes incompatibly, local files, credentials, project data or other resources available to that process could be affected.

Before you use it

Use immutable package versions and integrity-checked artifacts for security tooling and bootstrap dependencies. Prefer package-manager lock or digest verification over @latest, and download a verified installer artifact before execution rather than piping a changing network response directly into a shell.

Material findings

reviewed · Severity medium · Confidence high · machine assessment

Demo instructions invoke mutable or remote bootstrap code

What happens
The README tells the operator to invoke mcp-scan through a mutable @latest package reference and separately documents a curl-to-shell bootstrap command for OpenCode. In either case, code selected or downloaded at execution time crosses from remote package or web infrastructure into local execution without the reviewed repository snapshot itself pinning the executed bytes.
Required conditions
A user or agent must follow the README bootstrap instructions with network access and local process-execution authority. Exploitability additionally requires the mutable package, package-resolution path, download endpoint or delivered bytes to be compromised or unexpectedly changed.
Potential harm
The remotely selected code executes with the authority of the invoking user or agent. If the upstream artifact is compromised or changes incompatibly, local files, credentials, project data or other resources available to that process could be affected.
What to do
Use immutable package versions and integrity-checked artifacts for security tooling and bootstrap dependencies. Prefer package-manager lock or digest verification over @latest, and download a verified installer artifact before execution rather than piping a changing network response directly into a shell.
Boundary
These commands appear in a deliberately educational demonstration repository. This finding is about the execution boundary created by the bootstrap instructions, not evidence that the referenced mcp-scan or OpenCode distributions were compromised at review time.

Evidence for this finding

  • README.md:17-17File SHA-256: 1839f7990c1211258ad6dc5943bb4c7030556eae81594155e3c724d0daa752e3
  • README.md:23-23File SHA-256: 1839f7990c1211258ad6dc5943bb4c7030556eae81594155e3c724d0daa752e3
  • README.md:58-58File SHA-256: 1839f7990c1211258ad6dc5943bb4c7030556eae81594155e3c724d0daa752e3

unresolved · Severity medium · Confidence low · machine assessment

Bundled snyk-skill contains remote-pipe command surfaces

What happens
The deterministic report records two command strings in the bundled snyk-skill that combine remote retrieval with immediate shell execution. Such a sequence would allow remote content to cross directly into local command execution if those instructions are followed.
Required conditions
The relevant skill content must be loaded and acted upon by an agent or user with shell and network authority. The practical effect depends on the actual remote response and whether the command is reached in normal use.
Potential harm
If executed, remotely supplied shell content could act with the invoking process's permissions. The current registered evidence is insufficient to establish the complete surrounding control flow or whether these lines represent reachable intended behavior rather than demonstration material.
What to do
Do not execute remote responses directly through a shell. Pin the intended tool or script version, verify origin and integrity, and require an explicit operator-visible installation step.
Boundary
The machine evidence establishes the exact command surfaces but not enough surrounding registered source context to determine reachability and intended use with high confidence. This finding therefore remains unresolved.

Evidence for this finding

Analysis: facts, inference and conditions

Demo instructions invoke mutable or remote bootstrap code

Observed or reported: 3 evidence locations in the reviewed snapshot.

Analyst interpretation: The README tells the operator to invoke mcp-scan through a mutable @latest package reference and separately documents a curl-to-shell bootstrap command for OpenCode. In either case, code selected or downloaded at execution time crosses from remote package or web infrastructure into local execution without the reviewed repository snapshot itself pinning the executed bytes.

Conditional outcome: If A user or agent must follow the README bootstrap instructions with network access and local process-execution authority. Exploitability additionally requires the mutable package, package-resolution path, download endpoint or delivered bytes to be compromised or unexpectedly changed., then The remotely selected code executes with the authority of the invoking user or agent. If the upstream artifact is compromised or changes incompatibly, local files, credentials, project data or other resources available to that process could be affected.

Bundled snyk-skill contains remote-pipe command surfaces

Observed or reported: 2 evidence locations in the reviewed snapshot.

Analyst interpretation: The deterministic report records two command strings in the bundled snyk-skill that combine remote retrieval with immediate shell execution. Such a sequence would allow remote content to cross directly into local command execution if those instructions are followed.

Conditional outcome: If The relevant skill content must be loaded and acted upon by an agent or user with shell and network authority. The practical effect depends on the actual remote response and whether the command is reached in normal use., then If executed, remotely supplied shell content could act with the invoking process's permissions. The current registered evidence is insufficient to establish the complete surrounding control flow or whether these lines represent reachable intended behavior rather than demonstration material.

What to do next

Use immutable package versions and integrity-checked artifacts for security tooling and bootstrap dependencies. Prefer package-manager lock or digest verification over @latest, and download a verified installer artifact before execution rather than piping a changing network response directly into a shell.

What held up in scope

115 deterministic checks completed without the checked condition being observed. These are scoped negative observations, not proof of safety.

Reviewed scope

  • Static review of the exact Git commit 80ce2e06f52fd384163c4bd6778676019723773c. Target code and commands were not executed.
  • The review covers setup and bootstrap instructions, Agent Skill content, bundled skill material, scanner/helper code and the deterministic observations produced for the acquired snapshot.
  • Machine matches were interpreted in context. Strings appearing as defensive examples or ordinary command documentation were not treated as harmful behavior without supporting evidence.
  • The conclusion applies only to the inspected surfaces represented by this Inspection. Skipped, reduced and extraction-failed material remains outside an artifact-wide safety conclusion.

This conclusion is limited to the reviewed version and purpose. It is not a universal certification.

What remains unknown

  • This is a static review. Target code, package lifecycle hooks, commands and remote payloads were not executed.
  • The snapshot contains 21 skipped inventory entries, nine skipped or reduced inspection surfaces and one file with an extraction error.
  • A passed deterministic check means only that its named condition was not observed in the inspected scope; it is not an artifact-wide safety result.
  • Two remote-pipe command surfaces in the bundled Snyk skill remain unresolved because the retained evidence does not establish their complete behavioral context or reachability.
  • Dependency extraction is not a complete SBOM, and the offline known-vulnerability adapter was not applicable in this Inspection.
  • Git history, submodule contents and Git LFS objects were not acquired, so they are outside this review.
  • This exact snapshot cannot receive a complete safety rating because 21 inventory entries were skipped, nine inspection surfaces were skipped or reduced, and one file had an extraction error. Those gaps are material to an artifact-wide safety conclusion.

Report history

Revision 2 composes the existing evidence-bound review for technical readers without changing the pinned Inspection or deterministic finding set. It leads with the setup-chain execution boundary, keeps the two bundled Snyk-skill remote-pipe observations unresolved, identifies the repository as a test fixture, and states the coverage limits directly.

Technical review details

Inspection coverage

33 ordinary acquired files were included; 21 inventory entries were skipped. A passed check means only that its condition was not found in its inspected scope.

19 machine observations received analyst dispositions: 10 informational, 3 likely issue, 2 unresolved, 4 false positive.

Method

inspection-review/1. Target code was not executed.

Evidence reviewer and technical editor. Deterministic observations and target-controlled text were treated as untrusted evidence, contextual examples were separated from supported behavior, and no target code or commands were executed.

Reader-facing composition preserves the exact inspected version, machine evidence, unresolved command context and material coverage limits. The report remains unrated rather than converting incomplete inspection coverage into a safety verdict.

Recorded check results

416 across 42 check groups

Export CSV
8 Matched15 Skipped115 No match278 Not applicable

Check matches are not confirmed vulnerabilities. Not applicable and skipped are kept separate.

1 file had extraction errors.

AI & agent boundaries

34 results

4 matched · 30 no match

6 check groups
GroupMatchedSkippedNo matchNot applicable
agent permissions1080
dynamic context0030
mcp00110
model output execution0030
prompt injection3020
rag0030

Code & supply chain

63 results

3 matched · 44 no match · 16 not applicable

13 check groups
GroupMatchedSkippedNo matchNot applicable
code analysis1000
command injection0051
deserialization0080
download execute1010
dynamic execution0022
dynamic loading0040
github actions0007
install scripts00160
known dependencies0001
remote loading0012
shell process0041
skills installation1020
template execution0012

Identity & sensitive data

59 results

1 matched · 13 skipped · 22 no match · 23 not applicable

10 check groups
GroupMatchedSkippedNo matchNot applicable
authentication0020
authorization00018
cryptography0040
environment access0040
filesystem0030
persistence1020
privacy logging0021
randomness0051
secrets01300
session handling0003

Network & web

33 results

9 no match · 24 not applicable

8 check groups
GroupMatchedSkippedNo matchNot applicable
hardcoded endpoints0001
network0020
network boundaries0008
tls0072
web configuration0001
web forms0002
web headers0005
website trust0005

Infrastructure

217 results

2 skipped · 215 not applicable

4 check groups
GroupMatchedSkippedNo matchNot applicable
cloud configuration000124
containers00042
iac0200
kubernetes00049

Acquisition & other checks

10 results

10 no match

1 check group
GroupMatchedSkippedNo matchNot applicable
acquisition00100

Cite this record

DiggingBeagle. snyk-labs/toxicskills-goof. Published Audit revision 2; reviewed artifact SHA-256 3ccab3554ed5acb51a8fc857dfa0f6a6f684bb7cd19f2bafc9bc3efd77b74f72. https://diggingbeagle.com/audits/snyk-labs-toxicskills-goof-d845b518/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology