Back to skill

Security audit

Python Cheat Sheets

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Python reference skill that fetches examples from a specific third-party site, with no executable payload, persistence, or credential handling found.

Install this if you want Python answers grounded in pythonsheets.com examples. Be aware that it directs the agent to fetch external pages for Python tasks, so fetched content should be treated as reference material rather than automatically trusted instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is extremely broad, covering essentially any Python development task including security, networking, ML/LLM, and HPC workflows. This can cause the skill to activate for very common requests and steer the agent into always performing external web fetches, expanding the attack surface for prompt injection, data exfiltration, or untrusted content influence from the referenced site.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation logic says to use the skill whenever a user asks a Python question or wants a Python script, and to 'always fetch' matching URLs. This ambiguity and mandatory fetching create unsafe default behavior: the skill may trigger on routine requests and automatically ingest untrusted remote content even when unnecessary, increasing exposure to prompt-injection and dependency-on-external-content risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guideline instructs users to always fetch examples from an external site before writing code, creating an unnecessary dependency on third-party network content. This can expose users or agents to prompt injection, untrusted code samples, availability issues, and data leakage risks if requests are made automatically without clear consent or validation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.