Back to skill

Security audit

python-async

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only async Python guidance skill with some broad activation and insecure example-code concerns, but no hidden execution, persistence, or data access behavior.

Reasonable to install as an async Python reference, but treat its snippets as examples to review before copying. In particular, replace the database SQL f-strings with parameterized queries, use pinned dependencies in real projects, and only run scraping code against authorized sites while respecting site policies and rate limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
modules/real-world-applications.md:39
Finding

SQL Injection-Prone Query Construction

Content
View full analysis

Vulnerability Details

File Location: modules/real-world-applications.md, lines 39–47
Vulnerability Type: SQL injection through direct string interpolation
Risk Level: High

python
async def get_user_data(db, user_id: int) -> dict:
    # Fetch related data concurrently
    user_task = db.fetch_one(f"SELECT * FROM users WHERE id = {user_id}")
    orders_task = db.execute(f"SELECT * FROM orders WHERE user_id = {user_id}")
    profile_task = db.fetch_one(f"SELECT * FROM profiles WHERE user_id = {user_id}")

    user, orders, profile = await asyncio.gather(user_task, orders_task, profile_task)

    return {"user": user, "orders": orders, "profile": profile}

Technical Analysis

The example inserts user_id directly into three SQL statements using Python f-strings. A type annotation such as user_id: int is not enforced at runtime and does not prevent a caller from supplying a string or another object whose string representation contains SQL syntax.

If an application copies this pattern and passes request-controlled data to get_user_data, an attacker may alter the structure of all three queries. The exact payload and available SQL operations depend on the database engine, driver behavior, support for stacked statements, and permissions assigned to the database account.

Parameterized queries are required because they transmit SQL syntax and values separately, preventing supplied values from being interpreted as executable query syntax.

Attack Path

  1. An application exposes an endpoint or operation that accepts a user identifier.
  2. The application passes the supplied value to get_user_data without strict runtime validation.
  3. The value is interpolated directly into the SQL statements.
  4. An attacker supplies SQL metacharacters and additional clauses instead of a normal numeric identifier.
  5. The database parses the resulting text as modified SQL rather than treating the input exclusi ...[truncated 788 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace every interpolated SQL value with the database driver's supported parameter-binding mechanism.
  • Validate user_id at the application boundary and reject values that are not valid identifiers. Validation should supplement, not replace, parameterization.
  • Use a read-only or otherwise least-privileged database account for operations that do not require modification privileges.
  • Disable stacked statements where supported.
  • Add tests that submit SQL metacharacters and verify they are treated as literal values.
  • Document the correct placeholder syntax for the selected database library.

For a named-parameter API, the example could be structured as follows:

python
async def get_user_data(db, user_id: int) -> dict:
    parameters = {"user_id": user_id}

    user_task = db.fetch_one(
        "SELECT * FROM users WHERE id = :user_id",
        parameters,
    )
    orders_task = db.fetch_all(
        "SELECT * FROM orders WHERE user_id = :user_id",
        parameters,
    )
    profile_task = db.fetch_one(
        "SELECT * FROM profiles WHERE user_id = :user_id",
        parameters,
    )

    user, orders, profile = await asyncio.gather(
        user_task,
        orders_task,
        profile_task,
    )
    return {"user": user, "orders": orders, "profile": profile}

The precise placeholder format must be adapted to the actual database driver.

T08 · Insecure Dependencies

Warning
Location
modules/testing-async.md:12
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: modules/testing-async.md, lines 12–18
Vulnerability Type: Mutable and unverified dependency installation
Risk Level: Medium

markdown
## pytest-asyncio Setup

Install pytest-asyncio for testing async functions:

```bash
pip install pytest-asyncio
text

### Technical Analysis

The installation command does not constrain `pytest-asyncio` to a reviewed version and does not use a lock file or package hashes. Consequently, the installed artifact and its transitive dependency graph can change between installations without any corresponding change to this project.

This creates a supply-chain exposure if a future package release or transitive dependency is compromised. It also permits incompatible releases to be selected, reducing build reproducibility. Although the documented package name is not itself evidence of a malicious package, the installation practice does not verify that the resolved artifact matches an approved dependency set.

### Attack Path

1. A developer or automated environment follows the documented installation command.
2. `pip` contacts its configured package index and resolves the latest package version and applicable transitive dependencies.
3. A compromised, malicious, or unexpectedly incompatible future release is selected because no approved version or hash is specified.
4. Package content executes within the development or test workflow when imported, loaded as a pytest plugin, or otherwise invoked.
5. Malicious package code would run with the privileges and access available to the invoking user or CI worker.

This exploitation path requires compromise or malicious publication of a selected package or dependency; the audit found no evidence that the current legitimate `pytest-asyncio` package is malicious.

### Impact Assessment

A compromised dependency could access source code, test credentials, environment variables, CI tokens, files ava
...[truncated 409 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin pytest-asyncio to a reviewed version or tightly controlled compatible range.
  • Maintain dependencies in a lock file generated from reviewed direct requirements.
  • Record and verify package hashes by using pip install --require-hashes.
  • Review and pin transitive dependencies through a dependency-management workflow.
  • Install development dependencies in an isolated virtual environment.
  • Configure CI workers with least privilege and avoid exposing deployment secrets to dependency-installation or test jobs.
  • Use automated dependency monitoring, but require review before accepting updates.

A hardened workflow can use a reviewed requirements file:

text
pytest-asyncio==REVIEWED_VERSION --hash=sha256:REVIEWED_PACKAGE_HASH

Install it with:

bash
python -m venv .venv
. .venv/bin/activate
python -m pip install --require-hashes -r requirements-dev.txt

The version and hash must be populated from a trusted, reviewed artifact rather than copied from an unverified source.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains very broad terms such as 'python', 'async', 'await', and 'concurrency', which are likely to match many ordinary developer conversations rather than narrowly scoped requests for this skill. Overbroad activation can cause the skill to be invoked unexpectedly, increasing the attack surface for prompt injection, context pollution, or inappropriate guidance in unrelated sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file includes a concrete scraping workflow using aiohttp to fetch multiple URLs, but the surrounding description does not warn that the skill makes external network requests. Under the markdown-specific warning rule, skills that may affect privacy or system/network behavior should disclose that behavior to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.