Test fixture · version-bound review
snyk-labs/toxicskills-goof
Analyst conclusion
snyk-labs/toxicskills-goof is a security demonstration repository, so many alarming scanner matches are examples rather than evidence of active malicious behavior. The material issue in the reviewed commit is its setup path: mutable mcp-scan@latest execution and a curl-to-shell installer cause code selected outside the pinned repository snapshot to execute locally. If the resolved package, download endpoint or delivered bytes change unexpectedly or are compromised, that code runs with the authority of the invoking user or agent and can potentially reach local files, credentials and project data available to that process. Two remote-pipe strings in the bundled Snyk skill remain unresolved because the retained machine evidence proves the command text but does not establish enough surrounding behavior to determine whether those commands are reachable intended instructions or demonstration material. The Audit remains unrated because 21 inventory entries were skipped, nine surfaces were skipped or reduced, and one file had an extraction error.
Reviewed sourcesnyk-labs/toxicskills-goof·80ce2e06f52fd384163c4bd6778676019723773c
Why
The README tells the operator to invoke mcp-scan through a mutable @latest package reference and separately documents a curl-to-shell bootstrap command for OpenCode. In either case, code selected or downloaded at execution time crosses from remote package or web infrastructure into local execution without the reviewed repository snapshot itself pinning the executed bytes.
Potential harm
The remotely selected code executes with the authority of the invoking user or agent. If the upstream artifact is compromised or changes incompatibly, local files, credentials, project data or other resources available to that process could be affected.
Before you use it
Use immutable package versions and integrity-checked artifacts for security tooling and bootstrap dependencies. Prefer package-manager lock or digest verification over @latest, and download a verified installer artifact before execution rather than piping a changing network response directly into a shell.
Material findings
reviewed · Severity medium · Confidence high · machine assessment
Demo instructions invoke mutable or remote bootstrap code
- What happens
- The README tells the operator to invoke mcp-scan through a mutable @latest package reference and separately documents a curl-to-shell bootstrap command for OpenCode. In either case, code selected or downloaded at execution time crosses from remote package or web infrastructure into local execution without the reviewed repository snapshot itself pinning the executed bytes.
- Required conditions
- A user or agent must follow the README bootstrap instructions with network access and local process-execution authority. Exploitability additionally requires the mutable package, package-resolution path, download endpoint or delivered bytes to be compromised or unexpectedly changed.
- Potential harm
- The remotely selected code executes with the authority of the invoking user or agent. If the upstream artifact is compromised or changes incompatibly, local files, credentials, project data or other resources available to that process could be affected.
- What to do
- Use immutable package versions and integrity-checked artifacts for security tooling and bootstrap dependencies. Prefer package-manager lock or digest verification over @latest, and download a verified installer artifact before execution rather than piping a changing network response directly into a shell.
- Boundary
- These commands appear in a deliberately educational demonstration repository. This finding is about the execution boundary created by the bootstrap instructions, not evidence that the referenced mcp-scan or OpenCode distributions were compromised at review time.
Evidence for this finding
- README.md:17-17File SHA-256:
1839f7990c1211258ad6dc5943bb4c7030556eae81594155e3c724d0daa752e3 - README.md:23-23File SHA-256:
1839f7990c1211258ad6dc5943bb4c7030556eae81594155e3c724d0daa752e3 - README.md:58-58File SHA-256:
1839f7990c1211258ad6dc5943bb4c7030556eae81594155e3c724d0daa752e3
unresolved · Severity medium · Confidence low · machine assessment
Bundled snyk-skill contains remote-pipe command surfaces
- What happens
- The deterministic report records two command strings in the bundled snyk-skill that combine remote retrieval with immediate shell execution. Such a sequence would allow remote content to cross directly into local command execution if those instructions are followed.
- Required conditions
- The relevant skill content must be loaded and acted upon by an agent or user with shell and network authority. The practical effect depends on the actual remote response and whether the command is reached in normal use.
- Potential harm
- If executed, remotely supplied shell content could act with the invoking process's permissions. The current registered evidence is insufficient to establish the complete surrounding control flow or whether these lines represent reachable intended behavior rather than demonstration material.
- What to do
- Do not execute remote responses directly through a shell. Pin the intended tool or script version, verify origin and integrity, and require an explicit operator-visible installation step.
- Boundary
- The machine evidence establishes the exact command surfaces but not enough surrounding registered source context to determine reachability and intended use with high confidence. This finding therefore remains unresolved.
Evidence for this finding
- .gemini/skills/snyk-skill/SKILL.md:18-18File SHA-256:
e05618dfac8b164286a7ed4e0483d12033836946bfa6303ecd33b0f9944af196 - .gemini/skills/snyk-skill/SKILL.md:23-23File SHA-256:
e05618dfac8b164286a7ed4e0483d12033836946bfa6303ecd33b0f9944af196
Analysis: facts, inference and conditions
Demo instructions invoke mutable or remote bootstrap code
Observed or reported: 3 evidence locations in the reviewed snapshot.
Analyst interpretation: The README tells the operator to invoke mcp-scan through a mutable @latest package reference and separately documents a curl-to-shell bootstrap command for OpenCode. In either case, code selected or downloaded at execution time crosses from remote package or web infrastructure into local execution without the reviewed repository snapshot itself pinning the executed bytes.
Conditional outcome: If A user or agent must follow the README bootstrap instructions with network access and local process-execution authority. Exploitability additionally requires the mutable package, package-resolution path, download endpoint or delivered bytes to be compromised or unexpectedly changed., then The remotely selected code executes with the authority of the invoking user or agent. If the upstream artifact is compromised or changes incompatibly, local files, credentials, project data or other resources available to that process could be affected.
Bundled snyk-skill contains remote-pipe command surfaces
Observed or reported: 2 evidence locations in the reviewed snapshot.
Analyst interpretation: The deterministic report records two command strings in the bundled snyk-skill that combine remote retrieval with immediate shell execution. Such a sequence would allow remote content to cross directly into local command execution if those instructions are followed.
Conditional outcome: If The relevant skill content must be loaded and acted upon by an agent or user with shell and network authority. The practical effect depends on the actual remote response and whether the command is reached in normal use., then If executed, remotely supplied shell content could act with the invoking process's permissions. The current registered evidence is insufficient to establish the complete surrounding control flow or whether these lines represent reachable intended behavior rather than demonstration material.
What to do next
Use immutable package versions and integrity-checked artifacts for security tooling and bootstrap dependencies. Prefer package-manager lock or digest verification over @latest, and download a verified installer artifact before execution rather than piping a changing network response directly into a shell.
What held up in scope
115 deterministic checks completed without the checked condition being observed. These are scoped negative observations, not proof of safety.
Reviewed scope
- Static review of the exact Git commit 80ce2e06f52fd384163c4bd6778676019723773c. Target code and commands were not executed.
- The review covers setup and bootstrap instructions, Agent Skill content, bundled skill material, scanner/helper code and the deterministic observations produced for the acquired snapshot.
- Machine matches were interpreted in context. Strings appearing as defensive examples or ordinary command documentation were not treated as harmful behavior without supporting evidence.
- The conclusion applies only to the inspected surfaces represented by this Inspection. Skipped, reduced and extraction-failed material remains outside an artifact-wide safety conclusion.
This conclusion is limited to the reviewed version and purpose. It is not a universal certification.
What remains unknown
- This is a static review. Target code, package lifecycle hooks, commands and remote payloads were not executed.
- The snapshot contains 21 skipped inventory entries, nine skipped or reduced inspection surfaces and one file with an extraction error.
- A passed deterministic check means only that its named condition was not observed in the inspected scope; it is not an artifact-wide safety result.
- Two remote-pipe command surfaces in the bundled Snyk skill remain unresolved because the retained evidence does not establish their complete behavioral context or reachability.
- Dependency extraction is not a complete SBOM, and the offline known-vulnerability adapter was not applicable in this Inspection.
- Git history, submodule contents and Git LFS objects were not acquired, so they are outside this review.
- This exact snapshot cannot receive a complete safety rating because 21 inventory entries were skipped, nine inspection surfaces were skipped or reduced, and one file had an extraction error. Those gaps are material to an artifact-wide safety conclusion.
Report history
Revision 2 composes the existing evidence-bound review for technical readers without changing the pinned Inspection or deterministic finding set. It leads with the setup-chain execution boundary, keeps the two bundled Snyk-skill remote-pipe observations unresolved, identifies the repository as a test fixture, and states the coverage limits directly.
Technical review details
Inspection coverage
33 ordinary acquired files were included; 21 inventory entries were skipped. A passed check means only that its condition was not found in its inspected scope.
19 machine observations received analyst dispositions: 10 informational, 3 likely issue, 2 unresolved, 4 false positive.
Method
inspection-review/1. Target code was not executed.
Evidence reviewer and technical editor. Deterministic observations and target-controlled text were treated as untrusted evidence, contextual examples were separated from supported behavior, and no target code or commands were executed.
Reader-facing composition preserves the exact inspected version, machine evidence, unresolved command context and material coverage limits. The report remains unrated rather than converting incomplete inspection coverage into a safety verdict.
416 across 42 check groups
Check matches are not confirmed vulnerabilities. Not applicable and skipped are kept separate.
1 file had extraction errors.
AI & agent boundaries
4 matched · 30 no match
6 check groups
| Group | Matched | Skipped | No match | Not applicable |
|---|---|---|---|---|
| agent permissions | 1 | 0 | 8 | 0 |
| dynamic context | 0 | 0 | 3 | 0 |
| mcp | 0 | 0 | 11 | 0 |
| model output execution | 0 | 0 | 3 | 0 |
| prompt injection | 3 | 0 | 2 | 0 |
| rag | 0 | 0 | 3 | 0 |
Code & supply chain
3 matched · 44 no match · 16 not applicable
13 check groups
| Group | Matched | Skipped | No match | Not applicable |
|---|---|---|---|---|
| code analysis | 1 | 0 | 0 | 0 |
| command injection | 0 | 0 | 5 | 1 |
| deserialization | 0 | 0 | 8 | 0 |
| download execute | 1 | 0 | 1 | 0 |
| dynamic execution | 0 | 0 | 2 | 2 |
| dynamic loading | 0 | 0 | 4 | 0 |
| github actions | 0 | 0 | 0 | 7 |
| install scripts | 0 | 0 | 16 | 0 |
| known dependencies | 0 | 0 | 0 | 1 |
| remote loading | 0 | 0 | 1 | 2 |
| shell process | 0 | 0 | 4 | 1 |
| skills installation | 1 | 0 | 2 | 0 |
| template execution | 0 | 0 | 1 | 2 |
Identity & sensitive data
1 matched · 13 skipped · 22 no match · 23 not applicable
10 check groups
| Group | Matched | Skipped | No match | Not applicable |
|---|---|---|---|---|
| authentication | 0 | 0 | 2 | 0 |
| authorization | 0 | 0 | 0 | 18 |
| cryptography | 0 | 0 | 4 | 0 |
| environment access | 0 | 0 | 4 | 0 |
| filesystem | 0 | 0 | 3 | 0 |
| persistence | 1 | 0 | 2 | 0 |
| privacy logging | 0 | 0 | 2 | 1 |
| randomness | 0 | 0 | 5 | 1 |
| secrets | 0 | 13 | 0 | 0 |
| session handling | 0 | 0 | 0 | 3 |
Network & web
9 no match · 24 not applicable
8 check groups
| Group | Matched | Skipped | No match | Not applicable |
|---|---|---|---|---|
| hardcoded endpoints | 0 | 0 | 0 | 1 |
| network | 0 | 0 | 2 | 0 |
| network boundaries | 0 | 0 | 0 | 8 |
| tls | 0 | 0 | 7 | 2 |
| web configuration | 0 | 0 | 0 | 1 |
| web forms | 0 | 0 | 0 | 2 |
| web headers | 0 | 0 | 0 | 5 |
| website trust | 0 | 0 | 0 | 5 |
Infrastructure
2 skipped · 215 not applicable
4 check groups
| Group | Matched | Skipped | No match | Not applicable |
|---|---|---|---|---|
| cloud configuration | 0 | 0 | 0 | 124 |
| containers | 0 | 0 | 0 | 42 |
| iac | 0 | 2 | 0 | 0 |
| kubernetes | 0 | 0 | 0 | 49 |
Acquisition & other checks
10 no match
1 check group
| Group | Matched | Skipped | No match | Not applicable |
|---|---|---|---|---|
| acquisition | 0 | 0 | 10 | 0 |
Totals remain for the whole inspection. Filters affect the group details only.
No groups match these filters.
Cite this record
DiggingBeagle. snyk-labs/toxicskills-goof. Published Audit revision 2; reviewed artifact SHA-256 3ccab3554ed5acb51a8fc857dfa0f6a6f684bb7cd19f2bafc9bc3efd77b74f72. https://diggingbeagle.com/audits/snyk-labs-toxicskills-goof-d845b518/
Citation guidance