Back to skill

Security audit

Pharmaclaw Pharmacology Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill runs a local, SMILES-based pharmacology profiling script and does not show hidden access, persistence, exfiltration, or destructive behavior.

Install only if you need local research-oriented ADME and drug-likeness screening from SMILES. Treat results as approximate heuristics, not clinical, safety, regulatory, or medical advice, and keep downstream chaining to toxicology or IP workflows under explicit user control.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/chain_entry.py:207
Finding

Malformed JSON Causes Unhandled Process Termination

Content
View full analysis

Vulnerability Details

File Location: scripts/chain_entry.py, lines 207–210
Vulnerability Type: Unhandled input-parsing exception
Risk Level: Low

Vulnerable Code:

python
if args.input_json:
    input_data = json.loads(args.input_json)
else:
    input_data = json.load(sys.stdin)

Technical Analysis

Attacker-controlled JSON is parsed before the general exception handler that begins later in main(). If either json.loads() or json.load() receives malformed JSON, it raises json.JSONDecodeError outside that handler. The process consequently terminates instead of returning the documented structured JSON error response.

This behavior contradicts the error-handling guarantee in SKILL.md that all errors produce valid JSON and never crash. Depending on the execution environment, the uncaught exception can also write a Python traceback to standard error, exposing runtime details such as local source paths.

Attack Path

  1. An attacker or untrusted caller invokes the script with malformed JSON, for example:
    bash
    python scripts/chain_entry.py --input-json '{"smiles":'
    
    Alternatively, malformed JSON can be supplied through standard input.
  2. json.loads() or json.load() attempts to parse the supplied value.
  3. The parser raises json.JSONDecodeError.
  4. Because parsing occurs outside the exception handler, the process exits abnormally.
  5. The caller receives no standard error-schema response and may receive a traceback through standard error.

Impact Assessment

Exploitation requires only the ability to provide input to the script and does not grant elevated privileges, arbitrary code execution, filesystem access, or persistence. The impact is limited to invocation-level denial of service, disruption of pipeline consumers expecting valid JSON, and possible disclosure of local paths or runtime implementation details through traceback output.

Remediation
View remediation

Remediation Suggestions

Move argument and standard-input parsing inside the protected exception-handling block. Catch json.JSONDecodeError explicitly and return the same structured error schema used for other failures.

Recommended hardening steps:

  1. Wrap both json.loads(args.input_json) and json.load(sys.stdin) in try/except.
  2. Return a concise validation warning such as Invalid JSON input without embedding traceback or internal exception details.
  3. Verify that the parsed top-level value is a JSON object before calling .get().
  4. Add regression tests for malformed JSON, empty standard input, JSON arrays, scalar JSON values, and excessively large inputs.
  5. Consider enforcing an input-size limit at the calling boundary to reduce resource-exhaustion risk.

Example:

python
try:
    if args.input_json:
        input_data = json.loads(args.input_json)
    else:
        input_data = json.load(sys.stdin)

    if not isinstance(input_data, dict):
        raise ValueError("Input JSON must be an object")

    # Continue normal processing here.
except json.JSONDecodeError:
    output = {
        "agent": "pharma-pharmacology",
        "version": "1.1.0",
        "smiles": "",
        "status": "error",
        "report": {},
        "risks": [],
        "recommend_next": ["toxicology", "ip-expansion"],
        "confidence": 0.0,
        "warnings": ["Invalid JSON input"],
        "timestamp": datetime.now(timezone.utc).isoformat(),
    }
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is unusually broad for a specialized pharmacology tool, including generic terms like pharmacology, absorption, distribution, metabolism, excretion, and solubility. That can cause the skill to activate during general scientific or biomedical conversations where the user did not intend to invoke predictive drug-screening logic, increasing the chance of irrelevant, misleading, or over-relied-on output in sensitive health or research contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill presents heuristic ADME and pharmacology predictions as polished analytical output without an explicit warning that they are non-clinical, approximate, and unsuitable for medical, safety, or regulatory decision-making. In a drug discovery or health-adjacent setting, users may overtrust these predictions, leading to poor screening choices or inappropriate conclusions about safety, efficacy, or human use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises itself as a pharmacology/ADME profiling agent, but on both success and error paths it recommends an unrelated "ip-expansion" workflow. In an agentic system, downstream recommendations influence control flow; this can steer users or orchestration into out-of-scope actions, creating confused-deputy behavior, data leakage to unnecessary components, or unauthorized workflow chaining.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.