Back to skill

Security audit

ssgep-single-sample-expression

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed RNA-seq analysis workflow skill with expected command and file-writing needs, but users should review its broad triggers and unpinned package installs before use.

Install and run this skill only in a project directory or isolated environment with data you intend to process. Review package installation commands first, prefer pinned lockfiles where possible, and require confirmation before running long Bash/R/Python workflows or writing report outputs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:36
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:36-44
Vulnerability Type: Unpinned dependencies from mutable package registries
Risk Level: Medium

Vulnerable Code

r
install.packages(c('plotly','shiny','bslib','DT','circlize','RColorBrewer','writexl'), type='binary')
if (!require('BiocManager', quietly=TRUE)) install.packages('BiocManager', type='binary')
BiocManager::install(c('DESeq2','edgeR','limma','WGCNA','Rsubread',
  'ComplexHeatmap','clusterProfiler','enrichplot','AnnotationDbi','org.Ppasinensa.eg.db'), ask=FALSE)
text
pip install python-docx python-pptx matplotlib pandas openpyxl

Technical Analysis

The setup instructions install numerous R, Bioconductor, and Python packages without exact version constraints, integrity hashes, lockfiles, or explicitly constrained repositories. Package resolution therefore depends on mutable registry state at installation time, preventing reproducible verification of the reviewed dependency set.

This creates a supply-chain exposure if a registry, maintainer account, package release, dependency, or configured package mirror is compromised. It may also introduce incompatible or vulnerable future releases. The audit found no evidence that any named package is currently malicious; the issue is the unsafe dependency-resolution process.

Attack Path

  1. An attacker compromises a relevant package, transitive dependency, maintainer account, registry, or package mirror.
  2. The attacker publishes or serves a malicious release that satisfies the unconstrained package request.
  3. A user or agent follows the documented installation commands.
  4. The package manager resolves and installs the attacker-controlled artifact because no approved version or cryptographic hash is enforced.
  5. Malicious installation hooks or runtime code execute under the account running R or pip.
  6. Because the skill declares Bash and Write permissions, execution in an ...[truncated 674 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an explicitly reviewed version.
  2. Generate and commit an R renv.lock file covering CRAN, Bioconductor, and transitive dependencies.
  3. Use a hash-locked Python requirements file, such as:
    text
    pip install --require-hashes -r requirements.txt
    
  4. Configure explicit trusted CRAN, Bioconductor, and Python package indexes rather than inheriting arbitrary user or system mirrors.
  5. Download dependencies in a controlled build process, verify checksums or signatures where supported, and install from an approved internal artifact repository.
  6. Perform dependency vulnerability and provenance scanning before publishing updated lockfiles.
  7. Run installation and analysis under a dedicated, non-administrative account or isolated container with only the minimum required filesystem access.
  8. Separate dependency installation from normal skill execution and require user approval before package changes.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description contains broad activation phrases such as requests to '做表达谱分析', '打包项目案例', or generate '论文三格式', which can match generic bioinformatics or document-generation requests beyond the narrowly intended RNA-seq workflow. Overbroad routing can cause the agent to invoke this high-complexity pipeline in unintended contexts, leading to excessive tool use, unreviewed data processing, or inappropriate execution of downstream scripts on user-provided inputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase set includes a generic expression-profile term that can activate on broad, ordinary bioinformatics requests rather than only the narrowly intended single-sample/no-replicate workflow. This can cause unintended invocation of a Bash/Write-capable skill, increasing the chance of overbroad execution, file writes, or user confusion about which analysis mode is being applied.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The output-oriented trigger phrase is broad and may match generic requests to generate paper-style deliverables, even when the user is not asking for this specific transcriptomics pipeline. In context, the skill has Bash and Write permissions, so accidental activation could lead to unnecessary file generation or execution of analysis steps outside the user's intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.