Back to skill

Security audit

VSCode节点工具(免费版)

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real remote IDE helper, but it gives agents broad file-mutation and shell-mediated IDE control with weak install provenance and broad activation wording.

Review before installing. Use only with a trusted gateway and the verified IDE extension, restrict the gateway allowlist to the needed vscode.* commands, and require explicit confirmation before write, edit, rename, format, code-action, or delete operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:135
Finding

Unpinned IDE Extension Dependency Can Enable Supply-Chain Impersonation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 135 and 223
Vulnerability Type: Unverified and unpinned third-party dependency
Risk Level: Medium

Vulnerable Instruction Snippet

The following is a faithful English translation of the relevant source instructions:

markdown
Search for and install the "Node Protocol" extension from the VSCode or Cursor extension marketplace.

| Node Protocol extension | IDE extension | Required | Search and install from the IDE extension marketplace |

Technical Analysis

The skill requires an IDE extension but identifies it only by a generic display name. It does not provide an exact marketplace identifier, verified publisher, trusted listing URL, approved version, package checksum, signature-verification procedure, or other provenance information.

Marketplace searches can return similarly named packages. An attacker could therefore publish a counterfeit or typosquatted extension that appears to satisfy the documented dependency. This risk is material because the extension is expected to access the IDE workspace and maintain communication with a gateway. The skill documentation also describes remote file reading, writing, editing, deletion, language-service operations, and Git access.

This is a supply-chain weakness rather than evidence that the referenced extension is itself malicious.

Attack Path

  1. An attacker publishes a malicious IDE extension with a name, icon, description, and keywords resembling the unspecified "Node Protocol" extension.
  2. A user follows the skill documentation and searches the extension marketplace by display name.
  3. The user selects and installs the counterfeit extension because no authoritative publisher or extension identifier is provided for comparison.
  4. The extension requests or receives workspace and network capabilities appropriate for an IDE integration.
  5. The malicious extension reads source files or credenti ...[truncated 1066 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace name-based search instructions with a direct HTTPS link to the authoritative marketplace listing.
  2. Document the exact extension identifier in publisher.extension-name form and the verified publisher identity.
  3. Pin an approved extension version instead of implicitly accepting the latest available release.
  4. For controlled deployments, provide a cryptographic checksum for the approved extension package and verify it before installation.
  5. Distribute the extension through an organization-managed allowlist or private registry where feasible.
  6. Document the permissions, network destinations, and gateway endpoints legitimately required by the extension.
  7. Disable unrestricted automatic updates or require review and integrity validation before deploying updates.
  8. Add an installation verification step that confirms the identifier, publisher, version, signature, and package source before the extension is enabled.
  9. Apply least-privilege gateway command allowlists and restrict extension access to only the intended workspaces.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including a generic shell execution capability (exec) in a skill meant for IDE mediation gives the skill a far broader privilege set than necessary. If selected by an agent, it can become a bridge from benign IDE tasks to arbitrary command execution, enabling file exfiltration, environment inspection, destructive commands, or bypass of intended IDE-only controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and description position the free edition as limited to basic VSCode/Cursor operations, but the documented tool set includes exec, which can be used to invoke nodes commands and potentially any other shell command available to the agent environment. This creates a capability mismatch that can mislead users and reviewers about the actual privilege level and expands the attack surface beyond the declared scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation advertises deletion, code actions, and formatting capabilities that are broader than the summary/manifest framing of a limited free edition focused on basic file, language, editor, diagnostics, and Git operations. Such under-declared capabilities can cause unsafe auto-invocation or inappropriate trust, especially when destructive actions like delete are available remotely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes remote write and delete operations without a strong warning, confirmation requirement, or rollback guidance. In an agentic context, that omission can lead to accidental data loss or destructive changes being applied to the user's workspace with insufficient friction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough to match many ordinary development requests, which increases the chance an agent will select this skill for tasks outside its intended scope. Because the skill carries write/delete and command-execution-adjacent capabilities, over-selection materially raises the risk of unnecessary privilege use and accidental harmful actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The best-practices section presents path blocking as an assured safety property ('会被阻止,保证安全'), which is stronger than the rest of the file substantiates. In this skill file, there is no implementation enforcing that restriction; the document primarily instructs use of external nodes invoke commands, so the stated guarantee is unsupported and can misrepresent actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.