Back to skill

Security audit

journal-club-slides

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent slide-building skill with expected local document processing and no evidence of hidden execution, persistence, credential handling, or exfiltration.

Before installing, expect this skill to process research PDFs locally and create working folders, crops, slide-generation files, decks, and render-QA outputs. If dependencies are installed, prefer pinned versions or a reviewed requirements file for better reproducibility.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/python-pptx-render-qa-first-pass.md:8
Finding

Unpinned Third-Party Dependencies in Environment Setup Guidance

Content
View full analysis

Vulnerability Details

File Location: references/python-pptx-render-qa-first-pass.md, line 8
Vulnerability Type: Unpinned third-party dependencies and insufficient package-source verification
Risk Level: Medium

Vulnerable Snippet

markdown
- `python3 -m venv` + local installs (`pymupdf`, `python-pptx`, `pillow`, `markitdown`) solved missing-PyMuPDF problems without relying on system Python.

Technical Analysis

The workflow recommends installing four third-party Python packages without specifying exact versions, cryptographic hashes, a reviewed lockfile, or a trusted package index. A virtual environment provides dependency isolation but does not verify package integrity or provenance.

Consequently, dependency resolution can retrieve different package versions across runs. The environment could receive a compromised upstream release, dependency-confusion package, or malicious transitive dependency. Python packages may execute arbitrary code during installation through build backends and may also execute code when imported by the presentation-generation workflow.

The referenced package names do not themselves establish malicious behavior, and the project contains no embedded malicious script. The issue is the unsafe, non-reproducible dependency-installation guidance.

Attack Path

  1. An Agent follows the documented setup guidance and creates a local virtual environment.
  2. It installs the listed packages without version or hash constraints.
  3. The package resolver contacts its configured package source and resolves the latest compatible packages and transitive dependencies.
  4. An attacker compromises an upstream release, controls a configured package source, or introduces a dependency-confusion candidate.
  5. The malicious package is selected and installed.
  6. Attacker-controlled code executes during package build, installation, or later import with the privileges of the Agent process.

Impact Assessment

Successful exploi ...[truncated 620 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define reviewed dependencies in a version-controlled requirements or lock file using exact versions.

  2. Generate and verify cryptographic hashes for every direct and transitive dependency.

  3. Install with hash enforcement, for example:

    bash
    python3 -m venv .venv
    .venv/bin/python -m pip install --require-hashes -r requirements.txt
    
  4. Configure an explicit trusted package index or an internally controlled package mirror rather than inheriting arbitrary user-level index settings.

  5. Review transitive dependencies and package provenance before updating the lock file.

  6. Perform dependency installation and document processing inside a least-privileged sandbox or container with restricted filesystem and network access.

  7. Separate dependency resolution from production execution: resolve and review updates in a controlled environment, then deploy only the approved lock file.

  8. Add automated dependency and software-composition scanning to detect known vulnerable or compromised versions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.