Back to skill

Security audit

python-debugpy

Security checks for vulnerabilities and agentic risk

Overview

This skill provides straightforward Python debugging instructions with one disclosed dependency-installation caveat.

Before using the debugpy fallback command, prefer installing debugpy in an isolated virtual environment and pinning a reviewed version. Keep debug servers bound to localhost and only attach to processes you own or have explicit approval to inspect.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Runtime Installation of a Third-Party Debugging Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 24
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Complete Code Snippet:

bash
python3 -c "import debugpy" || python3 -m pip install debugpy

Technical Analysis

The documented fallback command installs debugpy dynamically when the initial import fails. The installation does not specify an approved version, package hash, lockfile, or explicitly trusted package index. Consequently, the package and its transitive dependencies are resolved from mutable repository state at execution time.

Package installation and subsequent import can execute third-party code in the local environment. Although the package name is consistent with the intended debugging functionality and there is no evidence that the skill deliberately selects a malicious package, the command creates a supply-chain exposure and makes installations non-reproducible.

Attack Path

  1. debugpy is absent from the active Python environment, causing python3 -c "import debugpy" to fail.
  2. Shell short-circuit evaluation invokes python3 -m pip install debugpy.
  3. pip resolves an unpinned release and its dependencies using the configured package index.
  4. If the index, selected release, dependency, or local package-index configuration has been compromised, attacker-controlled package content is installed.
  5. Installation behavior or subsequent use of debugpy executes that content with the permissions of the user running the command.

Impact Assessment

Successful supply-chain compromise could allow arbitrary code execution under the invoking user's account. The attacker could access or alter files, environment variables, source code, and credentials available to that user and could affect any debugging target accessible with the same privileges. The command does not itself request administrative privileges, establish persistence, or de ...[truncated 113 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove automatic dependency installation from the debugging command path and require explicit user approval before modifying the Python environment.
  • Pin debugpy to a reviewed version, for example through a locked requirements file rather than an unconstrained pip install.
  • Use hash verification, such as pip's --require-hashes, for the selected package and all transitive dependencies.
  • Install from an explicitly approved package index and prevent unexpected fallback to untrusted or attacker-controlled indexes.
  • Prefer an isolated virtual environment with minimal permissions instead of installing into a shared or privileged environment.
  • Periodically review and update the pinned version after checking upstream security advisories and release provenance.
  • Keep debugpy out of the project's runtime dependencies unless the project explicitly requires it, as already advised elsewhere in the skill.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.