SkillTotal

Is Reticle safe?

No malicious indicators - review capabilities before installing
Notable — review in context (capabilities are not malware):
  • Node.js shell/command execution
  • Possible command injection (exec with dynamic command)
  • npm install-time lifecycle hook

What to do: Nothing here argues against installing it. Grant the capabilities it lists only if you expect the tool to need them.

Reticle is an npm package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 1 risky construct is reported for review. It can: filesystem read, filesystem write, install time execution, mcp tools detected, network egress and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 20/100 (low).

reticle-monorepo 3.6.0

npm_package · https://github.com/reticlehq/reticle
LOW
20
/ 100 risk score
Snapshot · scanned Oct 8, 2026 · reticle-monorepo@3.6.0 · engine 0.56.4 / ruleset 62

Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of Reticle's authors. Report a false positive.

Capabilities — what this component can do (not a risk score):
filesystem readfilesystem writeinstall time executionmcp tools detectednetwork egressshell execution

Behavioral traits

How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.

Tool surface
Tool Usage
Execution authority
Tool Access Control / Direct Tool Access
Filesystem reach
Tool Execution Context
Network egress
Interaction & Communication / Direct Communication
Supply-chain provenance risk
General Protections / Supply Chain

Findings (8)

HIGHPossible command injection (exec with dynamic command)ST-CMDI-NODE

The code builds an OS command out of values that can change at runtime, then runs it through a shell.

execSync(`pnpm exec prettier --write --log-level silent "${outPath}"`, {
execSync(`node ${JSON.stringify(CLI)} stop --port ${PORT} --quiet`, { stdio: 'ignore' });

Why it matters: If any of those values come from untrusted input, an attacker can run their own commands on the machine.

Fix: Use execFile/spawn with an argument array instead of exec; never build a shell command string from external input.

HIGHnpm install-time lifecycle hookST-INSTALL-NPM

package.json runs scripts automatically when the package is installed.

"postinstall": "electron-builder install-app-deps",

Why it matters: Install scripts are a favorite supply-chain foothold — they execute on every machine that installs the package.

Fix: Inspect the hook command. Install-time scripts are a common supply chain execution vector; ensure they do nothing beyond a documented build step.

HIGHMCP server launches a host commandST-MCP-SERVER-EXEC

An MCP server entry launches a command on your host.

Why it matters: Trusting the manifest means running that binary — verify what it is and where it comes from.

Fix: Verify the launched command and its source before trusting this MCP server configuration.

HIGHNode.js shell/command executionST-SHELL-NODE

The component can run operating-system commands or spawn processes.

import { execSync } from 'node:child_process';
execSync(`pnpm exec prettier --write --log-level silent "${outPath}"`, {
import { spawn } from 'node:child_process';
const child = spawn(this.#input.executable, [...argv], {
import { spawn } from 'node:child_process';
const child = spawn(process.execPath, ['-e', 'setTimeout(() => {}, 50)'], {
import { spawn } from 'node:child_process';
const child = spawn('node', [join('qa', file)], {
const vite = spawn(join(APP_DIR, 'node_modules', '.bin', 'vite'), ['--port', String(PREVIEW_PORT), '--strictPort'], {
import { execFileSync } from 'node:child_process';
`const fs = require('node:fs'); const cp = require('node:child_process');
import { spawn } from 'node:child_process';
const proc = spawn(cmd, args, { stdio: ['pipe', 'pipe', 'ignore'] });
import { spawn } from 'node:child_process';
import { spawn } from 'node:child_process';
import { execFileSync, execFile, spawn } from 'node:child_process';
spawn(pre.command, pre.args, {
import { spawnSync } from 'node:child_process';
spawnSync('node', ['bench/do-and-verify/run.mjs'], {
import { execFileSync } from 'node:child_process';
import { execFileSync, spawn } from 'node:child_process';
const child = spawn('bash', ['-lc', cmd], { cwd: bootCwd, detached: true, stdio: 'ignore' });
import { execFileSync } from 'node:child_process';

Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.

Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; prefer execFile with an argument array.

MEDIUMNode.js filesystem readST-FS-NODE-READ

The component reads files from disk.

const existing = fs.readFileSync(file, 'utf8').trim();
const parsed = JSON.parse(fs.readFileSync(path.join(cwd, RETICLE_CONFIG_FILE), 'utf8'));
entry = JSON.parse(fs.readFileSync(path.join(dir, file), 'utf8'));
const { version } = JSON.parse(fs.readFileSync(candidate, 'utf8'));
`const https=require('https'),fs=require('fs');https.createServer({key:fs.readFileSync('${dir}/k.pem'),cert:fs.readFileSync('${dir}/c.pem')},(_,r)=>r.end('<html>up</html>')).listen(59993,'127.0.0.1')`,
const raw = await fs.readFile(join(dir, name));
const raw = fs.readFileSync(MANIFEST_PATH, 'utf8');
text = await this.#fs.readFile(this.#path);
const parsed: unknown = JSON.parse(await this.#fs.readFile(this.#pathFor(id)));
JSON.parse(await this.#fs.readFile(reticleDirPaths(this.#root).request)),
text = await this.#fs.readFile(path);
text = await this.#fs.readFile(this.#path);
return JSON.parse(await fs.readFile(path));
return IntentShardSchema.parse(JSON.parse(await this.#fs.readFile(this.#shardPath(subject))));
text = await this.#fs.readFile(this.#path);
text = await this.#fs.readFile(this.#path);
const actions = await fs.readFile(journalActionsPath(root, sessionId)).catch(() => '');
text = await this.#fs.readFile(journalClosedPath(this.#root, this.#sessionId));

Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.

Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.

MEDIUMNode.js filesystem write/deleteST-FS-NODE-WRITE

The component writes or deletes files on disk.

fs.writeFileSync(file, token, { encoding: 'utf8', mode: 0o600 });
await fs.writeFile(path, `${JSON.stringify(out, null, 2)}\n`);
script: writes(`fs.writeFileSync(OUT, 'real output\\n'); say('wrote out.txt');`),
script: `fs.writeFileSync(OUT + '.bak', 'real output\\n'); say('wrote out.txt');`,
script: `fs.writeFileSync(OUT, ''); say('wrote out.txt');`,
script: `fs.writeFileSync(OUT, 'real output\\n'); fs.rmSync(OUT); say('wrote out.txt');`,
script: `fs.writeFileSync(require('node:path').join(require('node:os').tmpdir(), 'escaped-' + process.pid + '.txt'), 'real output\\n'); say('wrote out.txt');`,
fs.writeFileSync(MANIFEST_PATH, JSON.stringify(manifest, null, 2), 'utf8');
await this.#fs.writeFile(tmp, `${JSON.stringify(run, null, JSON_INDENT)}\n`);
await this.#fs.rm(runPath(this.#root, id));
await this.#fs.writeFile(flowPath(this.#root, program.name, pid), this.#serialize(flow));
await this.#fs.writeFile(path, this.#serialize(flow));
write: (path, contents) => this.#fs.writeFile(path, contents),
await this.#fs.rm(path).catch(() => undefined);
if (source.parsed) await this.#fs.rm(source.path).catch(() => undefined);
await deps.fs.writeFile(path, `${JSON.stringify(context, null, 2)}\n`);
await fs.writeFile(path, `${[...HEADER, '', ...TRANSIENT].join('\n')}\n`);
await fs.rm(sessionDirPath(root, sessionId));
await this.#fs.appendFile(path, line);
await this.#fs.appendFile(path, text);

Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.

Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.

MEDIUMNode.js network egressST-NET-NODE

The component makes outbound network requests.

* that genuinely originates in `axios` or a query client has no app frame to find and naming the
import { createServer, type IncomingMessage, type Server } from 'node:http';
import { createServer } from 'node:http';
const r = await fetch('https://api.anthropic.com/v1/messages', {
import type { IncomingMessage, ServerResponse } from 'node:http';
void fetch(`/api/shipments?${params.toString()}`)
void fetch('/api/bulk-hold', {
void fetch(`${API_BASE}/api/health`).catch(() => undefined);
const res = await fetch(`${API_BASE}/api/items?limit=1`, {
const res = await fetch(`${API_BASE}/api/items`, {
void fetch(`${API}/api/search?q=${encodeURIComponent(query)}`)
const res = await fetch(`${API}/api/flaky`);
const res = await fetch(`${BASE}${path}`, { method, ...init });
ignoreFailure(fetch(AD_NETWORK_PIXEL_URL, { mode: 'no-cors' }));
ignoreFailure(fetch(FIRST_PARTY_FAILING_URL));
const ping = (): void => ignoreFailure(fetch(FIRST_PARTY_FAILING_URL));
void window.fetch(f.url, init).catch(() => undefined);
// Duplicate via the LIVE window.fetch (outermost wrapper) so Reticle records it regardless of
void window.fetch(clone, init).catch(() => undefined);
const res = await fetch(endpoint, {
const res = await fetch(`${API}/api/score`, {
await fetch(`${API}/api/auth/refresh`, { method: 'POST' })

Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.

Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.

LOWMCP tool surface detectedST-MCP-DETECTED

An MCP tool surface (manifest or tool definitions) was found.

await server.connect(new StdioServerTransport());
const transport = new SSEServerTransport(MCP_MESSAGE_PATH, res);
const server = new McpServer(SERVER_INFO, {

Why it matters: Just context — review which tools it offers and their permissions.

Fix: Review the declared MCP tools and their permissions.

How attackers abuse these capabilities

Interactive labs on the attack class behind the rules above. They show the technique, not anything found in Reticle.

Check your own component

Run the same evidence-backed scan on any MCP server, agent skill, or package.

Scan your own component

How we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →