Back to skill

Security audit

Bosszp

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent job-site scraping and visualization guide, but it needs review because it encourages bulk scraping of a named third-party platform with cookies/headers and weak install hygiene.

Review before installing or using. Only run this against data you are authorized to collect, avoid using personal/session cookies unless necessary and permitted, add clear rate limits and retention rules, and replace the install commands with a pinned reviewed requirements file after removing or verifying `flash`.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned and Questionable Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–22
Vulnerability Type: Supply-chain exposure through unpinned dependencies and a potentially unintended package name
Risk Level: Medium

Vulnerable Code:

bash
pip install scrapy
pip install flask pandas sqlalchemy pymysql
pip install flash

Technical Analysis

The installation instructions retrieve mutable, unpinned packages from the package index. Consequently, the installed code may differ over time and cannot be verified against reviewed versions or cryptographic hashes.

The separate installation of flash is particularly questionable because the documented application uses Flask, and flask is already installed by the preceding command. If flash is a typo, obsolete dependency, or similarly named package, users may install unintended third-party code. This creates exposure to typosquatting, dependency confusion, package takeover, and upstream compromise.

Python package installation can invoke package build backends or legacy setup mechanisms. A malicious package or release could therefore execute attacker-controlled code during installation. Installed packages may also execute malicious code later when imported by the crawler or web application.

Attack Path

  1. An attacker publishes, takes over, or compromises a package or release resolved by one of the unpinned names, particularly the questionable flash dependency.
  2. A user follows the Skill instructions and executes the documented pip install commands.
  3. pip resolves the current package release from the configured package index without an approved version or hash constraint.
  4. Malicious code executes through the package build or installation process, or is installed for execution when subsequently imported.
  5. The payload operates with the permissions of the user running pip and can access resources available to that account.

Impact Assessment

Success ...[truncated 552 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove pip install flash unless the package is genuinely required and its identity, ownership, source, and purpose have been verified. If Flask functionality was intended, retain only the correctly named Flask dependency.
  2. Record all reviewed dependencies and transitive dependencies in a lock file with exact versions.
  3. Require cryptographic hashes, for example by using a generated requirements file with pip install --require-hashes -r requirements.txt.
  4. Configure an approved package index or internal artifact repository rather than relying implicitly on arbitrary public-index resolution.
  5. Audit dependency names for typosquatting and review package provenance, maintainers, release history, and source repository before approval.
  6. Run installation inside an isolated virtual environment or container under a non-privileged account.
  7. Add automated dependency vulnerability and integrity scanning to the release process and regularly update the lock file through a controlled review procedure.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document provides end-to-end instructions for scraping a third-party job site, storing the results in MySQL, and analyzing them, but includes no warnings about terms-of-service restrictions, consent, personal data handling, or operational impact on the target site. Because the skill is specifically built for bulk collection from a named platform, the context makes the omission more dangerous: it facilitates scalable collection of potentially regulated or restricted data without compliance guardrails.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough to trigger on general requests about job data collection, salary analysis, or report generation without clearly limiting scope, authorization, or supported targets. In an agent setting, this can cause unintended invocation of a web-scraping workflow against third-party services, increasing the chance of unauthorized data collection or policy-violating automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.