Back to skill

Security audit

Cli Vscode

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about being a VSCode automation tool, but it needs review because it lets an agent persistently install arbitrary VSCode extensions and add workspace folders without built-in safeguards.

Install only if you are comfortable giving the agent control over VSCode. Require explicit approval before running install-extension, verify extension IDs and publishers yourself, and avoid adding sensitive folders to a workspace unless needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly advertises extension installation and workspace modification capabilities but does not warn that these actions change the local developer environment. In an agent context, this can lead to unreviewed persistence, introduction of risky extensions, or unintended project/workspace changes initiated on the user's machine.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 53)May include surrounding context.

Linux

bash
sudo ln -s /usr/share/code/bin/code /usr/local/bin/code

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Linux

bash
sudo ln -s /usr/share/code/bin/code /usr/local/bin/code

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents its title, help text, command descriptions, and later user-facing messages in Chinese, but there is no indication that users can opt into another language or locale. This creates a language-policy concern because the skill appears to enforce a specific locale by default rather than offering a choice.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · cli-vscode.py (reported line 36)May include surrounding context.

python
cmd.append(file)
    
    try:
        subprocess.run(cmd, check=True)
        if ctx.obj.get('json_output'):
            click.echo(json.dumps({"action": "open", "file": file or "VSCode"}))
        else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · cli-vscode.py (reported line 101)May include surrounding context.

python
cmd.append(file)
    
    try:
        subprocess.run(cmd, check=True)
        if ctx.obj.get('json_output'):
            click.echo(json.dumps({"action": "open", "file": file or "VSCode"}))
        else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
86% confidence
Finding

This command allows installation of an arbitrary VSCode extension based on user-controlled input. In an agent skill context, that is dangerous because extensions execute privileged code inside the editor environment and can access workspace contents, making this an indirect code-execution/supply-chain risk rather than a shell-injection issue.

Content

Scanner excerpt · cli-vscode.py (reported line 56)May include surrounding context.

python
cmd = ['code', '--install-extension', id]
    
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, check=True)
        if ctx.obj.get('json_output'):
            click.echo(json.dumps({"action": "install_extension", "id": id, "status": "success"}))
        else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · cli-vscode.py (reported line 75)May include surrounding context.

python
cmd = ['code', '--list-extensions']
    
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, check=True)
        extensions = result.stdout.strip().split('\n')
        
        if ctx.obj.get('json_output'):

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · cli-vscode.py (reported line 119)May include surrounding context.

python
"""显示 VSCode 状态"""
    # 检查 code 命令是否可用
    try:
        result = subprocess.run(['code', '--version'], capture_output=True, text=True)
        version = result.stdout.strip().split('\n')[0]
        
        status_info = {

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description is written in Chinese and presents its core purpose in that language without any indication of alternative language support or user opt-in. This can violate a language/locale policy when users are not explicitly given a choice of language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language instructions and capability descriptions are presented in Chinese, which effectively forces a specific language for users of the skill. There is no indication that this is a region-specific tool or that users can choose an alternate language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.