Security checks for vulnerabilities and agentic risk
Overview
This skill runs a local, SMILES-based pharmacology profiling script and does not show hidden access, persistence, exfiltration, or destructive behavior.
Install only if you need local research-oriented ADME and drug-likeness screening from SMILES. Treat results as approximate heuristics, not clinical, safety, regulatory, or medical advice, and keep downstream chaining to toxicology or IP workflows under explicit user control.
if args.input_json:
input_data = json.loads(args.input_json)
else:
input_data = json.load(sys.stdin)
Technical Analysis
Attacker-controlled JSON is parsed before the general exception handler that begins later in main(). If either json.loads() or json.load() receives malformed JSON, it raises json.JSONDecodeError outside that handler. The process consequently terminates instead of returning the documented structured JSON error response.
This behavior contradicts the error-handling guarantee in SKILL.md that all errors produce valid JSON and never crash. Depending on the execution environment, the uncaught exception can also write a Python traceback to standard error, exposing runtime details such as local source paths.
Attack Path
An attacker or untrusted caller invokes the script with malformed JSON, for example:
bash
Alternatively, malformed JSON can be supplied through standard input.
json.loads() or json.load() attempts to parse the supplied value.
The parser raises json.JSONDecodeError.
Because parsing occurs outside the exception handler, the process exits abnormally.
The caller receives no standard error-schema response and may receive a traceback through standard error.
Impact Assessment
Exploitation requires only the ability to provide input to the script and does not grant elevated privileges, arbitrary code execution, filesystem access, or persistence. The impact is limited to invocation-level denial of service, disruption of pipeline consumers expecting valid JSON, and possible disclosure of local paths or runtime implementation details through traceback output.
Remediation
View remediation
Remediation Suggestions
Move argument and standard-input parsing inside the protected exception-handling block. Catch json.JSONDecodeError explicitly and return the same structured error schema used for other failures.
Recommended hardening steps:
Wrap both json.loads(args.input_json) and json.load(sys.stdin) in try/except.
Return a concise validation warning such as Invalid JSON input without embedding traceback or internal exception details.
Verify that the parsed top-level value is a JSON object before calling .get().
Add regression tests for malformed JSON, empty standard input, JSON arrays, scalar JSON values, and excessively large inputs.
Consider enforcing an input-size limit at the calling boundary to reduce resource-exhaustion risk.
Example:
python
try:
if args.input_json:
input_data = json.loads(args.input_json)
else:
input_data = json.load(sys.stdin)
if not isinstance(input_data, dict):
raise ValueError("Input JSON must be an object")
# Continue normal processing here.
except json.JSONDecodeError:
output = {
"agent": "pharma-pharmacology",
"version": "1.1.0",
"smiles": "",
"status": "error",
"report": {},
"risks": [],
"recommend_next": ["toxicology", "ip-expansion"],
"confidence": 0.0,
"warnings": ["Invalid JSON input"],
"timestamp": datetime.now(timezone.utc).isoformat(),
}
The trigger list is unusually broad for a specialized pharmacology tool, including generic terms like pharmacology, absorption, distribution, metabolism, excretion, and solubility. That can cause the skill to activate during general scientific or biomedical conversations where the user did not intend to invoke predictive drug-screening logic, increasing the chance of irrelevant, misleading, or over-relied-on output in sensitive health or research contexts.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding
The skill presents heuristic ADME and pharmacology predictions as polished analytical output without an explicit warning that they are non-clinical, approximate, and unsuitable for medical, safety, or regulatory decision-making. In a drug discovery or health-adjacent setting, users may overtrust these predictions, leading to poor screening choices or inappropriate conclusions about safety, efficacy, or human use.
Content
No source excerpt is available for this finding.
Description-Behavior Mismatch
Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding
The skill advertises itself as a pharmacology/ADME profiling agent, but on both success and error paths it recommends an unrelated "ip-expansion" workflow. In an agentic system, downstream recommendations influence control flow; this can steer users or orchestration into out-of-scope actions, creating confused-deputy behavior, data leakage to unnecessary components, or unauthorized workflow chaining.