Back to skill

Security audit

Pet Sitter Intake Form Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a legitimate pet-sitting form generator, but its manifest tells the agent to place user-provided text into a shell command, which creates a review-worthy command execution risk.

Install only if you are comfortable with a skill that runs a local Python script through shell access. Avoid passing untrusted text into the form-generation prompt until the command template is changed to structured arguments, and consider omitting home-access fields unless needed. Completed intake PDFs may contain house-entry details, alarm codes, WiFi credentials, addresses, and emergency contacts, so store and share them securely.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skill.yaml:66
Finding

Shell Command Injection Through Raw User Input Interpolation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Non-Reproducible Dependency Resolution Through Unbounded Version Ranges

Content
View full analysis
=4.0.0 # YAML config support (optional but recommended) pyyaml>=6.0 ``` The documentation also recommends unrestricted installation: ```bash pip install reportlab pyyaml ``` and: ```bash pip install -r requirements.txt ``` ### Technical Analysis The dependency specifications provide only minimum versions and do not impose reviewed upper bounds, exact versions, or package hashes. Consequently, two installations performed at different times can resolve to different direct or transitive dependency versions. The package names appear legitimate, and the audit found no evidence that the currently referenced packages are malicious. The weakness is that future package releases or dependency graph changes can become part of the Skill without corresponding review of this repository. Integrity is also not verified because no hashes or locked dependency graph are supplied. ### Attack Path 1. A user or deployment system follows the documented installation instructions. 2. `pip` queries the configured package index and resolves the newest releases satisfying `reportlab>=4.0.0` and `pyyaml>=6.0`. 3. The resolved versions may differ from those used during development or security review. 4. If a future release or transitive dependency is compromised, malicious installation or runtime behavior can enter the environment. 5. That dependency code executes with the privileges of the installation process or Skill runtime. ### Impact Assessment The primary impacts are reduced build reproducibility and increased exposure to dependency supply-chain compromise. If a resolved package were compromised, its code could execute du ...[truncated 382 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to collect and generate documents containing highly sensitive personal and household security data, including alarm codes, entry methods, WiFi credentials, addresses, veterinarian contacts, and emergency information, yet it provides no privacy notice, minimization guidance, retention limits, or handling safeguards. In context, this is especially dangerous because pet-sitting intake forms routinely centralize everything needed for physical access to a home, making unauthorized disclosure materially harmful.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The authorization block states that the client gives permission for photos and videos to be shared before the later checkbox presents a Yes/No choice. That creates a consent contradiction and can lead to invalid or misleading authorization records, especially if users sign the overall agreement without noticing the later opt-out field. In the pet-sitting context, this is more concerning because client forms are intended to document permissions and may be relied on operationally or legally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code generates and saves a PDF containing sensitive personal and home-entry details collected elsewhere in the form, including alarm codes, Wi‑Fi passwords, addresses, and emergency contacts. Although it prints that the form was saved, it does not disclose that the output file may contain highly sensitive information or advise the user to handle/store it securely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest defines generic trigger phrases such as "client intake form", "new client form", and "boarding form" without narrowing context or providing exclusion conditions. In a natural-language entry point, these phrases could match ordinary conversation outside the intended pet-sitting skill scope.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified with a lower bound only, which allows future installs to resolve to different versions over time. This weakens supply-chain control and makes it harder to ensure the project consistently uses a version of reportlab that is known to be free of relevant security issues.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# Pet Sitter Intake Form Generator - Dependencies

# PDF generation (required)
reportlab>=4.0.0

# YAML config support (optional but recommended)
pyyaml>=6.0

Unverifiable Dependency: reportlab has 8 known advisory(ies) (CVE-2023-33733 (Reportlab vulnerable to remote code execution); CVE-2020-28463 (Server-side Request Forgery (SSRF) via img tags in reportlab); CVE-2019-19450 (ReportLab vulnerable to remote code execution via paraparser) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

ReportLab has multiple historical advisories, including issues that can become serious when generating PDFs from untrusted content. Because the manifest does not pin a version, there is no assurance that deployments will avoid vulnerable releases, and this skill’s purpose of producing client-facing PDFs makes the library directly relevant to the attack surface.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is not pinned to an exact version, so builds are non-reproducible and may unexpectedly pull in a vulnerable or incompatible PyYAML release. For a package with a history of unsafe deserialization issues, leaving version selection open increases supply-chain risk.

Content

Scanner excerpt · requirements.txt (reported line 7)May include surrounding context.

text
reportlab>=4.0.0

# YAML config support (optional but recommended)
pyyaml>=6.0

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

PyYAML has a well-known history of unsafe parsing and deserialization flaws when used on untrusted YAML. Since the version is not pinned, the project cannot demonstrate that installed environments avoid affected releases, and optional configuration support may still become dangerous if YAML input is later accepted from users or shared templates.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.