Back to plugin

Security audit

ACPX Runtime

Security checks for vulnerabilities and agentic risk

Overview

This package appears to be a real ACP runtime integration, but it grants broad host-level agent control and includes under-scoped automatic repair/install behavior that users should review before installing.

Install only if you trust this package to manage host-level coding-agent sessions. Review the permission mode, native agent enablement, MCP bridge settings, and any configured MCP server environment variables. Be especially cautious with automatic repair behavior, gateway restarts, ~/.acpx/config.json changes, and the unpinned npx adapter paths for kilocode and opencode.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly says not to ask for install permission first unless policy requires it, authorizing package installation and subsequent restart behavior without user consent. In a security context this is a severe violation because it normalizes silent code acquisition and execution on the host, materially increasing supply-chain and unauthorized-change risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger conditions are broad enough to match common requests about relaying or continuing work in external coding harnesses, which can cause the skill to activate in more situations than intended. In this skill, over-triggering is risky because activation can lead directly to session spawning, external tool control, and downstream install/repair behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/acp-router/SKILL.md (reported line 81)May include surrounding context.

md
3. For ACP harness thread creation, do not use `message` with `action=thread-create`; `sessions_spawn` is the only thread-create path.
4. Put requested work in `task` so the ACP session gets it immediately.
5. Set `agentId` explicitly unless ACP default agent is known.
6. Do not ask user to run slash commands or CLI when this path works directly.

Example:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The recovery policy instructs automatic local repair, verification, gateway restart, and retry behavior without a clear warning that the agent may modify the local environment. In practice this can lead to unexpected package changes or service restarts triggered by a normal user request, increasing the chance of unsafe autonomous system modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The direct acpx path includes concrete installation and repair commands that modify plugin-local dependencies, but it does not pair them with a clear consent requirement or warning about environment changes. This is dangerous because the skill is not merely descriptive; it is operational guidance for an agent that may execute those steps automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill references npx -y @kilocode/cli without a pinned version, so execution may fetch and run whatever package version is current at runtime. In a routing skill that explicitly drives external harnesses and may auto-repair tooling, this creates a supply-chain execution risk and undermines reproducibility.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The unpinned npx -y opencode-ai command allows runtime retrieval and execution of the latest published package, exposing the environment to malicious or compromised upstream releases. Because this skill is designed to route user requests into executable harness sessions, the context makes arbitrary package drift especially dangerous.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/.setup/service-D5hGWl5U.mjs:610
Evidence
const child = spawn(command, args, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/mcp-proxy.mjs:100
Evidence
const child = spawn(target.command, target.args, createTargetSpawnOptions());