Is Reticle safe?
- Node.js shell/command execution
- Possible command injection (exec with dynamic command)
- npm install-time lifecycle hook
What to do: Nothing here argues against installing it. Grant the capabilities it lists only if you expect the tool to need them.
Reticle is an npm package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 1 risky construct is reported for review. It can: filesystem read, filesystem write, install time execution, mcp tools detected, network egress and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 20/100 (low).
reticle-monorepo 3.6.0
Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of Reticle's authors. Report a false positive.
Behavioral traits
How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.
Findings (8)
The code builds an OS command out of values that can change at runtime, then runs it through a shell.
execSync(`pnpm exec prettier --write --log-level silent "${outPath}"`, {execSync(`node ${JSON.stringify(CLI)} stop --port ${PORT} --quiet`, { stdio: 'ignore' });Why it matters: If any of those values come from untrusted input, an attacker can run their own commands on the machine.
Fix: Use execFile/spawn with an argument array instead of exec; never build a shell command string from external input.
package.json runs scripts automatically when the package is installed.
"postinstall": "electron-builder install-app-deps",
Why it matters: Install scripts are a favorite supply-chain foothold — they execute on every machine that installs the package.
Fix: Inspect the hook command. Install-time scripts are a common supply chain execution vector; ensure they do nothing beyond a documented build step.
An MCP server entry launches a command on your host.
"command": "npx",
Why it matters: Trusting the manifest means running that binary — verify what it is and where it comes from.
Fix: Verify the launched command and its source before trusting this MCP server configuration.
The component can run operating-system commands or spawn processes.
import { execSync } from 'node:child_process';execSync(`pnpm exec prettier --write --log-level silent "${outPath}"`, {import { spawn } from 'node:child_process';const child = spawn(this.#input.executable, [...argv], {import { spawn } from 'node:child_process';const child = spawn(process.execPath, ['-e', 'setTimeout(() => {}, 50)'], {import { spawn } from 'node:child_process';const child = spawn('node', [join('qa', file)], {const vite = spawn(join(APP_DIR, 'node_modules', '.bin', 'vite'), ['--port', String(PREVIEW_PORT), '--strictPort'], {import { execFileSync } from 'node:child_process';`const fs = require('node:fs'); const cp = require('node:child_process');import { spawn } from 'node:child_process';const proc = spawn(cmd, args, { stdio: ['pipe', 'pipe', 'ignore'] });import { spawn } from 'node:child_process';const chrome = spawn(
import { spawn } from 'node:child_process';const chrome = spawn(
import { execFileSync, execFile, spawn } from 'node:child_process';spawn(pre.command, pre.args, {import { spawnSync } from 'node:child_process';spawnSync('node', ['bench/do-and-verify/run.mjs'], {import { execFileSync } from 'node:child_process';import { execFileSync, spawn } from 'node:child_process';const child = spawn('bash', ['-lc', cmd], { cwd: bootCwd, detached: true, stdio: 'ignore' });import { execFileSync } from 'node:child_process';Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.
Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; prefer execFile with an argument array.
The component reads files from disk.
const existing = fs.readFileSync(file, 'utf8').trim();
const parsed = JSON.parse(fs.readFileSync(path.join(cwd, RETICLE_CONFIG_FILE), 'utf8'));
entry = JSON.parse(fs.readFileSync(path.join(dir, file), 'utf8'));
const { version } = JSON.parse(fs.readFileSync(candidate, 'utf8'));`const https=require('https'),fs=require('fs');https.createServer({key:fs.readFileSync('${dir}/k.pem'),cert:fs.readFileSync('${dir}/c.pem')},(_,r)=>r.end('<html>up</html>')).listen(59993,'127.0.0.1')`,const raw = await fs.readFile(join(dir, name));
const raw = fs.readFileSync(MANIFEST_PATH, 'utf8');
text = await this.#fs.readFile(this.#path);
const parsed: unknown = JSON.parse(await this.#fs.readFile(this.#pathFor(id)));
JSON.parse(await this.#fs.readFile(reticleDirPaths(this.#root).request)),
text = await this.#fs.readFile(path);
text = await this.#fs.readFile(path);
text = await this.#fs.readFile(this.#path);
text = await this.#fs.readFile(this.#path);
return JSON.parse(await fs.readFile(path));
text = await this.#fs.readFile(path);
return IntentShardSchema.parse(JSON.parse(await this.#fs.readFile(this.#shardPath(subject))));
text = await this.#fs.readFile(path);
text = await this.#fs.readFile(this.#path);
text = await this.#fs.readFile(this.#path);
const actions = await fs.readFile(journalActionsPath(root, sessionId)).catch(() => '');
text = await this.#fs.readFile(journalClosedPath(this.#root, this.#sessionId));
text = await this.#fs.readFile(path);
text = await this.#fs.readFile(path);
text = await fs.readFile(path);
Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.
Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.
The component writes or deletes files on disk.
fs.writeFileSync(file, token, { encoding: 'utf8', mode: 0o600 });await fs.writeFile(path, `${JSON.stringify(out, null, 2)}\n`);script: writes(`fs.writeFileSync(OUT, 'real output\\n'); say('wrote out.txt');`),script: `fs.writeFileSync(OUT + '.bak', 'real output\\n'); say('wrote out.txt');`,script: `fs.writeFileSync(OUT, ''); say('wrote out.txt');`,script: `fs.writeFileSync(OUT, 'real output\\n'); fs.rmSync(OUT); say('wrote out.txt');`,script: `fs.writeFileSync(require('node:path').join(require('node:os').tmpdir(), 'escaped-' + process.pid + '.txt'), 'real output\\n'); say('wrote out.txt');`,fs.writeFileSync(MANIFEST_PATH, JSON.stringify(manifest, null, 2), 'utf8');
await this.#fs.writeFile(tmp, `${JSON.stringify(run, null, JSON_INDENT)}\n`);await this.#fs.rm(runPath(this.#root, id));
await this.#fs.writeFile(flowPath(this.#root, program.name, pid), this.#serialize(flow));
await this.#fs.writeFile(path, this.#serialize(flow));
await this.#fs.writeFile(
write: (path, contents) => this.#fs.writeFile(path, contents),
await this.#fs.rm(path);
await this.#fs.rm(path).catch(() => undefined);
if (source.parsed) await this.#fs.rm(source.path).catch(() => undefined);
await deps.fs.writeFile(path, `${JSON.stringify(context, null, 2)}\n`);await fs.rm(join(dir, name));
await fs.rm(path);
await fs.writeFile(path, `${[...HEADER, '', ...TRANSIENT].join('\n')}\n`);await fs.rm(sessionDirPath(root, sessionId));
await this.#fs.writeFile(
await this.#fs.appendFile(path, line);
await this.#fs.appendFile(path, text);
Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.
Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.
The component makes outbound network requests.
* that genuinely originates in `axios` or a query client has no app frame to find and naming the
import { createServer, type IncomingMessage, type Server } from 'node:http';import { createServer } from 'node:http';const r = await fetch('https://api.anthropic.com/v1/messages', {import type { IncomingMessage, ServerResponse } from 'node:http';void fetch(`/api/shipments?${params.toString()}`)void fetch('/api/dispatch', {void fetch('/api/bulk-hold', {void fetch(`${API_BASE}/api/health`).catch(() => undefined);const res = await fetch(`${API_BASE}/api/items?limit=1`, {const res = await fetch(`${API_BASE}/api/items`, {void fetch(`${API}/api/search?q=${encodeURIComponent(query)}`)const res = await fetch(`${API}/api/flaky`);const res = await fetch(`${BASE}${path}`, { method, ...init });fetch(url, {ignoreFailure(fetch(AD_NETWORK_PIXEL_URL, { mode: 'no-cors' }));ignoreFailure(fetch(FIRST_PARTY_FAILING_URL));
const ping = (): void => ignoreFailure(fetch(FIRST_PARTY_FAILING_URL));
void window.fetch(f.url, init).catch(() => undefined);
// Duplicate via the LIVE window.fetch (outermost wrapper) so Reticle records it regardless of
void window.fetch(clone, init).catch(() => undefined);
const res = await fetch(endpoint, {const res = await fetch(`${API}/api/score`, {fetch(url, {await fetch(`${API}/api/auth/refresh`, { method: 'POST' })Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.
Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.
An MCP tool surface (manifest or tool definitions) was found.
"mcpServers": {await server.connect(new StdioServerTransport());
const transport = new SSEServerTransport(MCP_MESSAGE_PATH, res);
const server = new McpServer(SERVER_INFO, {Why it matters: Just context — review which tools it offers and their permissions.
Fix: Review the declared MCP tools and their permissions.
How attackers abuse these capabilities
Interactive labs on the attack class behind the rules above. They show the technique, not anything found in Reticle.
Check your own component
Run the same evidence-backed scan on any MCP server, agent skill, or package.
Scan your own componentHow we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →