Back to skill

Security audit

WaveletWorldModel

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, coherent wavelet-modeling utility with a minor dependency-hygiene note but no hidden or high-impact behavior.

Review the dependency setup before installing: use a virtual environment and pinned, trusted NumPy and PyWavelets versions if you run the helper script. The skill otherwise appears limited to local wavelet-model computation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/wavelet_world_model.py:3
Finding

Unpinned Third-Party Dependency Installation Instruction

Content
View full analysis

Vulnerability Details

File Location: scripts/wavelet_world_model.py, lines 3–9
Vulnerability Type: Insecure dependency management and supply-chain exposure
Risk Level: Medium

Vulnerable Code

python
import numpy as np
try:
    import pywt
except ImportError:
    print("Error: The 'PyWavelets' library is required.")
    print("Please install it using: pip install PyWavelets")
    sys.exit(1)

Technical Analysis

When pywt is unavailable, the script instructs the user to install PyWavelets directly from the active pip package index without specifying an exact version, validating package hashes, or providing a reviewed lock file. NumPy is also imported without any declared or pinned version in the audited project.

As a result, dependency resolution may vary over time and depends on the user's pip configuration. If the configured package index, a resolved release, or a transitive dependency is compromised, attacker-controlled code could run during package installation or when the dependency is imported. The audit found no evidence that the legitimate PyWavelets package itself is malicious; the risk arises from the unsafe and non-reproducible installation process.

Attack Path

  1. A user runs the script in an environment where PyWavelets is not installed.
  2. The script displays the instruction pip install PyWavelets.
  3. The user executes that command using a package index configured locally or by the environment.
  4. pip resolves an unconstrained package release and its transitive dependencies without project-provided hash verification.
  5. If the index, selected release, or dependency chain has been compromised, malicious package code executes during installation or later import under the user's account.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user performing the installation or running the script. This could expose files, credentials, environment variables ...[truncated 279 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a reviewed dependency manifest covering both PyWavelets and NumPy.
  2. Pin exact dependency and transitive-dependency versions.
  3. Generate and verify cryptographic hashes for every resolved package.
  4. Replace the ad hoc installation message with a reproducible command, for example:
bash
python -m pip install --require-hashes -r requirements.txt
  1. Recommend installation in a dedicated virtual environment rather than the system Python environment.
  2. Use a trusted, explicitly configured package index and review dependency updates before changing the lock file.
  3. Add automated dependency vulnerability and integrity checks to the release process.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The usage section gives example prompts for invoking the skill, but it does not clearly define whether these are the only supported triggers or provide exclusion conditions. While the phrases are partly domain-specific, the activation guidance remains open-ended enough to create ambiguity about when the skill should activate versus when it should not.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.