Back to skill

Security audit

Ecommerce Data Export

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent ecommerce report-export helper, with no hidden code or malicious instructions found, though scheduled sending and unpinned dependencies deserve caution.

Before installing, confirm that any scheduled report feature requires your explicit opt-in, uses approved delivery destinations, and handles sales or pricing data according to your retention and sharing rules. Install dependencies in an isolated environment and prefer pinned package versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Python Dependencies Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–17
Vulnerability Type: Unpinned third-party Python dependencies
Risk Level: Medium

Code Snippet:

json
"kind": "pip",
"package": "pandas openpyxl",

Technical Analysis

The skill declares pandas and openpyxl without exact versions or integrity hashes. Consequently, installation resolves whichever compatible releases are available from the configured Python package index at installation time.

This makes installations non-reproducible and leaves the skill exposed to upstream package compromise, a compromised package index, malicious dependency substitution in an untrusted index, or future releases containing security regressions. Python packages distributed as source archives may execute build backend logic during installation; installed package code also executes when imported or invoked.

The declared package names are established packages, and the audited file does not specify a malicious source or contain evidence that either dependency is currently compromised. The issue is the absence of controls that ensure reviewed dependency artifacts are installed.

Attack Path

  1. An attacker compromises a declared package, one of its transitive dependencies, or a package index trusted by the installation environment.
  2. The attacker publishes or substitutes a malicious release matching the unconstrained dependency declaration.
  3. A user installs the skill dependencies after that release becomes available.
  4. pip resolves and installs the attacker-controlled artifact because no exact version or hash is enforced.
  5. Malicious code runs through package build hooks, installation-related behavior, or subsequent package import and use.

Impact Assessment

Exploited dependency code would generally run with the privileges of the account performing installation or executing the skill. It could access files, environment variables, credent ...[truncated 426 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin each direct dependency to an exact, reviewed version, for example:
    text
    pandas==REVIEWED_VERSION
    openpyxl==REVIEWED_VERSION
    
  2. Generate and commit a lock file that also pins all transitive dependencies.
  3. Require cryptographic hashes for every permitted artifact, such as by installing from a hash-locked requirements file with pip --require-hashes.
  4. Use an explicitly configured, trusted package index or an internally controlled artifact repository.
  5. Prefer reviewed binary wheels where appropriate and prevent unexpected source builds in deployment environments.
  6. Run dependency installation and skill execution as a non-privileged account in an isolated virtual environment or container.
  7. Add automated dependency vulnerability and provenance scanning, and update pinned versions through a controlled review process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises timed report generation and automatic sending but does not warn users about data export, file creation, persistence, or possible external delivery destinations. This is dangerous because users may unintentionally authorize recurring handling or transmission of potentially sensitive commercial data such as sales history, pricing, or competitor analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger examples are broad and do not clearly constrain when the skill should activate versus when it should defer, which can cause unintended invocation on loosely related user requests. In a skill that exports reports and may generate files on a schedule, ambiguous activation increases the chance of acting on user data without sufficiently explicit intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

整个技能描述、示例和安装标签均仅使用中文,未说明是否只能以中文交互,也未提供用户语言选择。按照语言/地区政策要求,若技能默认强制某一语言而无用户选择或合理业务限定,可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.