Back to skill

Security audit

Python Venv

Security checks for vulnerabilities and agentic risk

Overview

This Python environment skill is mostly purpose-aligned, but it tells agents to make environment-changing decisions with too little user confirmation and includes unsafe remote installer commands.

Install only if you are comfortable with the agent creating or reusing Python environments and installing dependencies after inspection. Do not run the documented curl-to-shell or Invoke-Expression uv installer commands without separate verification, and require confirmation before deleting .venv, creating environments, or installing packages from project files.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/troubleshooting.md:128
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md, lines 128–131
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Vulnerable Code

bash
# Linux/macOS
curl -LsSf https://astral.sh/uv/install.sh | sh

# Windows PowerShell
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

Technical Analysis

The documented commands retrieve mutable scripts from an external URL and immediately execute the returned content using sh or PowerShell's Invoke-Expression. They provide no opportunity to inspect the payload and perform no release-version pinning, cryptographic signature verification, or checksum validation.

The PowerShell command also uses -ExecutionPolicy ByPass, disabling an applicable process-level safeguard while executing the downloaded script. Although astral.sh appears associated with the recommended uv tool, reliance on the apparent legitimacy of a domain does not eliminate the supply-chain risk. Compromise of the upstream server, hosting infrastructure, DNS resolution, TLS trust chain, or installation script could turn the documented operation into arbitrary code execution without requiring changes to the reviewed Skill package.

This behavior exceeds the minimum privileges and capabilities needed for the Skill's declared Python environment-management functionality. The project already documents python3 -m venv as a built-in fallback, so executing an unverified remote installer is not necessary to create a Python virtual environment.

Attack Path

  1. A user invokes the Skill to create or repair a Python environment.
  2. The Skill determines that uv is unavailable.
  3. The troubleshooting instructions direct the agent or user to run one of the remote installation commands.
  4. The command retrieves the current response from https://astral.sh/uv/install.sh or https://astral.sh/uv/install.ps1.
  5. The response is passed directly t ...[truncated 935 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct download-to-shell examples from the troubleshooting documentation.
  2. Default to the built-in and locally available fallback when uv is absent:
    bash
    python3 -m venv .venv
    source .venv/bin/activate
    
  3. Prefer a trusted platform package manager that supports version pinning and package verification.
  4. If direct upstream installation is unavoidable:
    • Pin a specific release rather than using a mutable installation endpoint.
    • Download the artifact to a local file without executing it.
    • Verify its publisher signature or a SHA-256 checksum obtained through an independent trusted channel.
    • Allow the user to inspect the downloaded content.
    • Clearly disclose the source, version, destination, and commands that will be executed.
    • Request explicit user confirmation before execution.
    • Execute with ordinary user privileges and never request unnecessary administrator or root access.
  5. Do not use PowerShell -ExecutionPolicy ByPass with remotely retrieved content. Use signed scripts and the narrowest execution policy compatible with the verified installation procedure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (10)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The shell/PowerShell chaining pattern directly executes remote content without giving the user an opportunity to inspect it, which is a classic command-chaining abuse pattern. In a troubleshooting document for developer tooling, users are especially likely to copy-paste these commands, increasing the likelihood of accidental arbitrary code execution if the remote source is ever tampered with.

Content

Scanner excerpt · references/troubleshooting.md (reported line 128)May include surrounding context.

bash
# Linux/macOS
curl -LsSf https://astral.sh/uv/install.sh | sh

# Windows PowerShell
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description says the skill will 'Automatically detect project type and existing environments' and 'Minimize interruptions, only ask when necessary,' but it does not define specific trigger phrases, boundaries, or exclusion conditions. In a manifest-style markdown header, this broad behavior description could cause the skill to match generic Python setup situations without clear limits on when it should or should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These instructions direct the agent to create environments and install dependencies immediately based on detected files, without requiring confirmation or warning that the actions will modify the user's filesystem and potentially fetch untrusted packages. In an agent setting, that can lead to unintended environment mutation, dependency confusion exposure, or execution of package install hooks simply from heuristic detection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 'Do more, ask less' principle encourages autonomous execution of environment-changing commands without a consent checkpoint. In a security-sensitive agent context, minimizing prompts is less important than preventing silent package installation, environment creation, or command execution based on ambiguous repository state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document gives conflicting guidance: it first says to always ask the user before creating a new virtual environment, then later provides automation patterns that create one implicitly. In an agent skill, this can cause state-changing filesystem actions without explicit user consent, which is a real safety issue even if the action is not inherently destructive.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/patterns.md (reported line 172)May include surrounding context.

md
- Using `pip install` with system Python (always use venv)
- Installing packages globally
- Assuming third-party packages are available without explicit installation
- Overwriting existing virtual environment without checking first

## Allowed Without venv

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The troubleshooting guide includes irreversible deletion commands (rm -rf .venv and Remove-Item -Recurse -Force .venv) but does not explicitly warn that the existing environment will be removed and local installed packages in that environment will be lost. For markdown files, SQP-2 applies when descriptions omit warnings about behavior that can affect user data or system state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatically reusing and activating any detected existing environment is risky because the environment may be project-external, stale, attacker-prepared, or contain unexpected interpreter/package state. Running inside such an environment can contaminate results, alter system state, or trigger execution paths the user did not intend.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The forbidden-actions section says not to overwrite an existing virtual environment without checking first, but the earlier shortcut patterns can still create .venv after checking only a limited set of names. This inconsistency can lead an agent to create an unnecessary or conflicting environment, causing workspace confusion or dependency drift.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to fetch and immediately execute a remote installation script (curl ... | sh / irm ... | iex). This bypasses normal integrity review and makes users trust live network content at execution time; if the upstream server, transport, DNS, or distribution channel is compromised, arbitrary code runs on the user's machine.

Content

Scanner excerpt · references/troubleshooting.md (reported line 128)May include surrounding context.

bash
# Linux/macOS
curl -LsSf https://astral.sh/uv/install.sh | sh

# Windows PowerShell
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

Static analysis

No suspicious patterns detected.