Back to skill

Security audit

python-packaging

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Python packaging skill whose publishing commands are purpose-aligned, but users should review before running upload or cleanup examples.

Install this skill if you want Python packaging guidance. Before running examples, especially uv publish or the CI publishing workflow, verify the target registry, credentials, version, and package contents; only run rm -rf build/ dist/ from the intended project directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · modules/uv-workflow.md (reported line 72)May include surrounding context.

uv build --no-isolation

Clear build cache

rm -rf build/ dist/

text

### Import Errors

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad terms such as 'python', 'packaging', 'pip', and 'distribution', which are likely to match many unrelated user requests and cause unintended activation of this skill. In an agent setting, overbroad activation can route users into packaging or publishing guidance when they did not intend it, increasing the chance of inappropriate commands being suggested or executed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quick-start flow includes 'uv publish' without an explicit warning that this uploads package artifacts to PyPI, which may be irreversible and could expose private, unreviewed, or malicious code publicly. In a skill intended for agents, omission of that warning is risky because users may follow or auto-run the sequence as a standard setup procedure without recognizing the external publication step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file includes uv publish examples for TestPyPI and PyPI, which send package contents and associated metadata to remote services. The surrounding documentation does not include any warning or disclosure about external transmission or the consequences of publishing, which is a safety-relevant omission for markdown guidance.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
97% confidence
Finding

The trigger 'uv' is extremely short and ambiguous, making accidental activation likely in unrelated contexts where 'UV' refers to ultraviolet, shell aliases, abbreviations, or non-packaging topics. While lower impact than explicit dangerous commands, this increases the chance of incorrect skill routing and unnecessary exposure to packaging and publishing instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.