Back to skill

Security audit

Render Stl Png

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward STL-to-PNG renderer, with some ordinary setup and availability risks users should understand before running it.

Install only if you are comfortable with the wrapper creating a cached Python virtual environment and downloading Pillow. Prefer reviewing or preinstalling dependencies yourself, and avoid rendering untrusted or very large STL files or using extreme --size values unless you run it with resource limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/render_stl_png.sh:18
Finding

Unpinned Dependencies Are Installed Automatically at Runtime

Content
View full analysis

Vulnerability Details

File Location: scripts/render_stl_png.sh:18-21
Vulnerability Type: Uncontrolled third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
if [[ ! -x "$VENV/bin/python" ]]; then
  python3 -m venv "$VENV"
  "$VENV/bin/pip" install --upgrade pip >/dev/null
  "$VENV/bin/pip" install pillow >/dev/null
fi

Technical Analysis

The recommended wrapper automatically downloads and installs the latest available versions of pip and pillow. It does not specify exact versions, verify package hashes, use a lock file, or explicitly select a trusted package index.

Package installation may execute package-controlled build or installation logic. Consequently, the effective code executed by the Skill depends on mutable external repository content and the user's local pip configuration. Relevant configuration can include an alternative index or mirror that is not controlled by the project.

The cached environment also persists after execution. Once a dependency has been installed, later invocations continue using that installation without verifying its integrity.

Attack Path

  1. A user invokes the wrapper as recommended in SKILL.md.
  2. The cached virtual environment does not yet exist, causing the installation block to run.
  3. pip connects to its configured package index or mirror.
  4. A compromised package release, repository, mirror, or pip configuration supplies malicious dependency content.
  5. Package-controlled code executes during installation or when the renderer imports Pillow.
  6. The malicious code runs with the privileges of the user who invoked the wrapper and remains present in the cached virtual environment.

Impact Assessment

Successful exploitation can result in arbitrary code execution under the invoking user's account. The malicious dependency could access files and credentials available to that user, alter generated output, commu ...[truncated 358 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin reviewed versions of both pip and Pillow rather than installing the latest releases.
  • Store dependencies in a version-controlled lock or requirements file.
  • Require cryptographic hashes, for example by using pip install --require-hashes -r requirements.txt.
  • Configure an explicit trusted package index instead of implicitly accepting local pip index configuration.
  • Avoid automatically upgrading pip during normal Skill execution.
  • Separate dependency installation from rendering and require an explicit setup action.
  • Verify the integrity of an existing cached environment before reusing it.
  • Consider using an isolated, prebuilt environment or a reviewed system package where deployment conditions permit.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_stl_png.py:271
Finding

Unbounded STL and Image Parameters Permit Resource Exhaustion

Content
View full analysis

Vulnerability Details

File Location: scripts/render_stl_png.py:101-102, scripts/render_stl_png.py:148-155, scripts/render_stl_png.py:271-274, and scripts/render_stl_png.py:358-365
Vulnerability Type: Uncontrolled memory allocation and computational complexity
Risk Level: Medium

Vulnerable Code

The complete input file is loaded into memory:

python
def read_stl(path: str) -> List[Tri]:
    with open(path, "rb") as f:
        data = f.read()

Coordinate bounds are accumulated into additional Python lists:

python
def bounds(tris: Sequence[Tri]) -> Tuple[Vec3, Vec3]:
    xs: List[float] = []
    ys: List[float] = []
    zs: List[float] = []
    for t in tris:
        for v in (t.a, t.b, t.c):
            xs.append(v[0])
            ys.append(v[1])
            zs.append(v[2])
    return (min(xs), min(ys), min(zs)), (max(xs), max(ys), max(zs))

The requested dimensions directly control quadratic allocations:

python
    img = Image.new("RGB", (size, size), bg_rgb)
    pix = img.load()
    zbuf = [[float("inf")] * size for _ in range(size)]

The command-line parameter has no upper bound:

python
    ap.add_argument("--stl", required=True)
    ap.add_argument("--out", required=True)
    ap.add_argument("--size", type=int, default=1024)
    ap.add_argument("--bg", default="#0b0f14")
    ap.add_argument("--color", default="#4cc9f0")
    ap.add_argument("--azim-deg", type=float, default=-35.0)
    ap.add_argument("--elev-deg", type=float, default=25.0)
    ap.add_argument("--fov-deg", type=float, default=35.0)
    ap.add_argument("--margin", type=float, default=0.08)

Technical Analysis

The renderer does not impose limits on the STL file size, parsed triangle count, output dimensions, or rendering workload.

f.read() loads the entire attacker-supplied file into memory. Parsing then creates triangle, vertex, face, normal, c ...[truncated 2059 chars]

Remediation
View remediation

Remediation Suggestions

  • Validate --size and reject values outside a conservative range, such as 1 through a deployment-specific maximum.
  • Set an explicit maximum output-pixel count in addition to per-dimension limits.
  • Check the STL file size with os.stat() before reading it and reject files above a documented threshold.
  • Enforce a maximum triangle count for both ASCII and binary STL input.
  • For binary STL files, validate the declared triangle count against the configured limit before parsing records.
  • Avoid collecting separate xs, ys, and zs lists; calculate bounds incrementally.
  • Stream or memory-map large input where practical instead of reading the entire file at once.
  • Replace the nested Python-list z-buffer with a more memory-efficient representation.
  • Reject non-finite coordinates and invalid numeric rendering parameters before geometry processing.
  • Run rendering with explicit memory, CPU, and execution-time limits when handling untrusted files.
  • Return a controlled validation error when any configured resource limit is exceeded.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
python3 scripts/render_stl_png.py \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script silently creates a persistent virtual environment under the user's cache directory and installs Python packages at runtime without any user-facing disclosure or consent. Even though it only installs Pillow and uses standard tooling, this behavior modifies the host environment and performs network/package-management actions that may be unexpected in a skill execution context, increasing supply-chain and trust risks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.