Back to skill

Security audit

Advanced ML Classification Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it can execute Python generated by a remote model with the user's local permissions, which needs careful review before installation.

Install only if you are comfortable with the skill sending some workflow data to OpenAI and potentially executing model-generated Python locally. Prefer running it in an isolated environment with no sensitive files or environment secrets, remove or disable remote code execution, pass API keys explicitly only when needed, and pin dependencies before production use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/advanced_ml_skill.py:661
Finding

Unrestricted Execution of Remotely Generated Python Code

Content
View full analysis

Vulnerability Details

File Location: scripts/advanced_ml_skill.py, lines 382–396 and 657–674
Vulnerability Type: Remote payload retrieval followed by unrestricted dynamic execution
Risk Level: Critical

Vulnerable Code:

python
if not self.openai_client:
    return fallback_code

prompt = self._build_code_prompt(algorithm_name)
try:
    response = self.openai_client.completions.create(
        model="code-davinci-002",
        prompt=prompt,
        max_tokens=900,
        temperature=0.2,
    )
    candidate = self._strip_code_fence(response.choices[0].text)
    if "def train_and_evaluate" not in candidate:
        return fallback_code
    return candidate + "\n"
except Exception:
    return fallback_code
python
error: Optional[str] = None
accuracy: Optional[float] = None
namespace: Dict[str, Any] = {}

try:
    exec(code, namespace)  # noqa: S102
    train_fn = namespace.get("train_and_evaluate")
    if not callable(train_fn):
        raise ValueError("生成代码中未定义 train_and_evaluate 函数。")

    score = train_fn(
        data_bundle["x_train_processed"],
        data_bundle["x_test_processed"],
        data_bundle["y_train"],
        data_bundle["y_test"],
        self.random_state,
        data_bundle["n_classes"],
    )
    accuracy = round(float(score), 4)

Technical Analysis

When an OpenAI client is configured, the application requests executable Python source code from a remote AI service. The only validation applied to the response is a substring check for def train_and_evaluate. This does not establish that the response contains only a safe model implementation.

Python code may contain executable top-level statements before or after the expected function. It can also import unrestricted modules and perform arbitrary actions from inside the function. The complete response is passed to exec with normal built-ins and the full per ...[truncated 1978 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove dynamic execution of remotely generated code. Map supported algorithm names to reviewed local estimator implementations instead.
  2. If code generation is retained as a user-facing feature, treat generated source strictly as display-only content and do not execute it.
  3. If execution is an unavoidable product requirement, run generated code in a disposable external sandbox or container with:
    • No host filesystem mounts.
    • No application secrets or API keys.
    • Outbound networking disabled.
    • A read-only base filesystem.
    • An unprivileged user and dropped Linux capabilities.
    • Strict CPU, memory, process, and execution-time limits.
    • Destruction of the environment after every execution.
  4. Use a narrow, structured model specification rather than generated source code—for example, permit the remote service to select from an allowlisted algorithm and validated numeric hyperparameters.
  5. Do not rely on substring checks, regular expressions, restricted globals, or AST filtering as the sole security boundary. Python cannot be safely sandboxed inside the same trusted process using these techniques alone.
  6. Add tests that reject generated content containing top-level statements, imports, filesystem access, network access, dynamic evaluation, or subprocess calls, even if isolated execution remains as defense in depth.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/app.py:109
Finding

Uploaded CSV Files Persist in Temporary Storage Without Cleanup

Content
View full analysis

Vulnerability Details

File Location: scripts/app.py, lines 109–112
Vulnerability Type: Insecure temporary-file lifecycle
Risk Level: Medium

Vulnerable Code:

python
if uploaded_file is not None:
    with tempfile.NamedTemporaryFile(delete=False, suffix=".csv") as tmp:
        tmp.write(uploaded_file.getvalue())
        data_path = str(Path(tmp.name))

Technical Analysis

Uploaded datasets are written to a temporary file with delete=False. No subsequent cleanup operation removes the file after successful processing or after an exception. Consequently, every uploaded CSV can remain on disk indefinitely.

Although NamedTemporaryFile normally creates a difficult-to-predict filename and restrictive file permissions, those protections do not address retention. Sensitive business or personal data may persist beyond the intended request lifetime. Repeated uploads can also accumulate and consume available storage.

The application reads the complete uploaded object with uploaded_file.getvalue() and does not impose an application-level size limit in this code, further increasing the resource-exhaustion risk.

Attack Path

  1. A user uploads a CSV through the Streamlit interface.
  2. The application creates a temporary file with deletion disabled.
  3. The model completes, fails, or the user abandons the session.
  4. Because there is no finally cleanup block, the temporary CSV remains on the host.
  5. Another process or user with sufficient local access can recover the retained data, or repeated uploads can progressively consume temporary-storage capacity.

Impact Assessment

The primary impact is unintended retention and possible local disclosure of uploaded datasets. The scope is limited to files uploaded through this application and to actors with access to the host or temporary storage. Repeated large uploads can also cause disk exhaustion, which may disrupt this Skill and other serv ...[truncated 31 chars]

Remediation
View remediation

Remediation Suggestions

  1. Track whether a temporary file was created and remove it in a finally block:
python
temp_path = None
try:
    if uploaded_file is not None:
        with tempfile.NamedTemporaryFile(delete=False, suffix=".csv") as tmp:
            tmp.write(uploaded_file.getvalue())
            temp_path = Path(tmp.name)
            data_path = str(temp_path)

    # Process the dataset here.
finally:
    if temp_path is not None:
        temp_path.unlink(missing_ok=True)
  1. Prefer parsing the uploaded CSV directly from its in-memory file-like object where the downstream architecture permits it.
  2. Enforce a conservative upload-size limit before loading the complete file into memory.
  3. Store temporary data only in a private directory with restrictive permissions.
  4. Add periodic cleanup for abandoned files as a secondary safeguard, while retaining immediate per-request cleanup as the primary control.
  5. Document data-retention behavior and avoid logging dataset contents or temporary paths unnecessarily.

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Automatic Installation of Unpinned and Unverified Dependencies

Content
View full analysis

Vulnerability Details

File Location: scripts/requirements.txt, lines 1–7; one_click_start.sh, line 16; scripts/run_demo.sh, lines 12–13
Vulnerability Type: Non-reproducible dependency installation without integrity verification
Risk Level: Medium

Vulnerable Code:

text
pandas>=2.0.0
scikit-learn>=1.3.0
xgboost>=2.0.0
lightgbm>=4.0.0
plotly>=5.20.0
streamlit>=1.35.0
openai>=1.30.0
bash
python -m pip install --disable-pip-version-check -q -r requirements.txt
bash
pip install --upgrade pip
pip install -r requirements.txt

Technical Analysis

All direct dependencies use open-ended minimum-version constraints. The startup and demonstration scripts automatically resolve and install whatever compatible versions are available at execution time. There are no exact version pins, package hashes, or locked transitive dependencies.

This makes installation non-reproducible and permits the effective codebase to change without changes to the reviewed project. A compromised future release, compromised transitive dependency, or unexpectedly incompatible package version could be installed automatically. Python package installation and later imports can execute package-controlled code.

No specific dependency in the reviewed file was confirmed to be malicious. The finding concerns the unsafe trust and update model created by mutable version ranges and automatic installation.

Attack Path

  1. A user runs one_click_start.sh or scripts/run_demo.sh.
  2. The script invokes pip against the open-ended dependency specification.
  3. Pip resolves the newest versions satisfying the minimum constraints, including unpinned transitive packages.
  4. If a selected direct or transitive release has been compromised or contains malicious installation/runtime code, that code is installed into the environment.
  5. Installation hooks or subsequent imports execute with the privileges of t ...[truncated 730 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace open-ended minimum constraints with a reviewed lock file containing exact versions for direct and transitive dependencies.
  2. Generate and verify cryptographic hashes, and install with hash enforcement, such as:
bash
python -m pip install --require-hashes -r requirements.lock
  1. Separate human-maintained top-level requirements from the generated deployment lock file.
  2. Update dependencies through a controlled process that includes review, vulnerability scanning, compatibility testing, and lock-file regeneration.
  3. Avoid installing dependencies automatically on every application startup. Build a pre-reviewed virtual environment, container image, or deployment artifact instead.
  4. Do not automatically upgrade pip in the demonstration script without selecting and reviewing a specific version.
  5. Configure pip to use an approved package index and consider package-signing or provenance controls where supported.
  6. Run dependency installation and the application as a dedicated unprivileged account with access only to required files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose centers on ML model/code generation, prediction execution, evaluation, visualization, and explanatory output. In contrast, the actual script solely creates a synthetic multiclass demo dataset and saves it as a CSV file. While such data generation could support an ML demo pipeline, none of the claimed core capabilities are implemented in this code chunk. Therefore the code's primary behavior is materially different from the declared description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends requests to external OpenAI services for code generation, which is not disclosed in the manifest description of a classification skill. Because prompts may include algorithm selection and later workflow outputs, this introduces an undisclosed network exfiltration path and dependence on a remote service outside the user's expected execution boundary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code path combines external code generation with immediate dynamic execution, creating a direct remote-to-runtime execution chain. In the skill context, this is more dangerous because the feature is not necessary to accomplish classification: the same algorithms already have safe local templates, so the risk is unjustified and exposes the environment to arbitrary code execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill executes generated Python without any explicit user-facing warning or confirmation, denying users informed consent for a dangerous action. In context, this materially increases risk because unsuspecting users may provide datasets or run the skill in privileged environments, unaware that arbitrary code could be executed.

Content

No source excerpt is available for this finding.

exec() call detected

High
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

The skill executes dynamically generated Python with exec() after sourcing that code from an external OpenAI completion API or fallback text. This creates an arbitrary code execution path inside the host process, allowing malicious or compromised model output to run with the skill's full permissions, including filesystem, network, and environment access.

Content

Scanner excerpt · scripts/advanced_ml_skill.py (reported line 661)May include surrounding context.

python
namespace: Dict[str, Any] = {}

        try:
            exec(code, namespace)  # noqa: S102
            train_fn = namespace.get("train_and_evaluate")
            if not callable(train_fn):
                raise ValueError("生成代码中未定义 train_and_evaluate 函数。")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises behavior that implies code generation and execution, local environment use, and file-writing capability, but it does not declare any tool scope such as permissions or allowed-tools. This weakens containment and informed review because consumers cannot tell what resources the skill is expected to access, increasing the risk of unintended filesystem or environment interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description states the skill provides beginner-friendly result interpretation in Chinese, and the workflow later reiterates generation of Chinese explanations. There is no indication that users can opt into another language or that the Chinese-only behavior is required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow explicitly states it will generate code using a remote model and then execute algorithm code, and it may also use another remote model for interpretation, yet there is no warning or consent mechanism for these impactful operations. This can expose data to third parties, trigger unexpected network activity, and run generated code in ways users may not anticipate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This step explicitly says the skill generates beginner-friendly Chinese interpretations. Because no language selection or opt-in mechanism is described anywhere in the file, the skill appears to impose a fixed locale on users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module description explicitly states that the skill generates beginner-friendly Chinese interpretations, and later prompts instruct the model to respond in Chinese. This imposes a fixed language behavior without any visible opt-in, fallback, or justification that the skill is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill automatically reads OPENAI_API_KEY from the environment and initializes an external API client even though this credential access and outbound integration are not clearly part of the stated local ML classification function. This broadens the trust boundary and can lead to undisclosed use of sensitive credentials or unexpected external data transfer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Silently sourcing an API credential from the environment without user-facing disclosure expands the skill's effective privileges and can surprise users about secret consumption and remote access. In combination with remote requests, it increases the chance of unintended credential use and hidden external dependency activation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The interpretation step transmits accuracy results, CV scores, search results, and error content to an external chat model without that behavior being clearly disclosed. While this is less severe than code execution, error messages and result metadata can still reveal sensitive dataset characteristics, environment details, or internal paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Both the task string and the system prompt instruct the model to produce Chinese explanations, creating a mandatory locale choice in natural-language behavior. The file does not provide a parameter or documented option for users to choose another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends model/result data to OpenAI APIs without a clear user-facing warning about external transmission. This is a transparency and data-handling vulnerability because users may assume local-only processing for an ML classification tool and unknowingly disclose potentially sensitive metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s natural-language UI and description are presented in Chinese, and the caption explicitly promises Chinese interpretation, with no apparent language selection or user opt-in. This can violate language/locale policy when a skill mandates a specific language rather than offering a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

When a file is uploaded, the code silently persists its contents to a temporary file on the local filesystem. Although this may be implementation-convenient, there is no visible notice near the upload flow or in comments/docstrings warning users that uploaded data will be stored locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The module docstring and inline comment are written in Chinese, which imposes a specific language in the skill's natural-language content without any opt-in or explanation that the skill is intentionally region-specific. Under the policy, locale or language constraints should either be optional for the user or clearly documented as justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description explicitly frames the skill as producing Chinese-language output without indicating that language is configurable or tied to a documented business requirement. This can improperly constrain downstream behavior, causing policy, accessibility, or user-expectation issues when users need another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The output schema requires the interpretation field to be in Chinese, creating a hard-coded language policy that excludes user choice. While not a code-execution risk, it can violate product language requirements, reduce accessibility, and cause unexpected behavior in multilingual deployments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The UI accepts an arbitrary local CSV path, which causes the skill to read data from the host filesystem, but the interface does not warn the user that local file access will occur. For a code file, this kind of file access should have some visible disclosure unless it is explicitly documented as part of the skill behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This CSV includes Chinese-language values such as education labels (for example, 本科, 硕士, 博士, 高中) while the file provides no accompanying note about expected language, locale, or user opt-in. Under the policy, forcing or assuming a specific language/locale without documentation can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file performs a file write operation by opening the target path in write mode, which will create or overwrite the output CSV. Aside from the minimal module docstring, there is no user-facing confirmation prompt, warning comment near the write, or explicit disclosure about the write behavior before execution.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower bound only, which allows future installs to resolve to different versions over time. This weakens reproducibility and can unintentionally pull in vulnerable or breaking releases through the direct package or its transitive dependency graph.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
pandas>=2.0.0
scikit-learn>=1.3.0
xgboost>=2.0.0
lightgbm>=4.0.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Because pandas is not pinned, it is impossible to verify from this manifest whether the installed version is affected by known advisories. In a data-processing skill this uncertainty matters, especially where parsing or deserialization-related functionality may be exercised indirectly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.