Back to skill

Security audit

Data Anomaly Detector

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed construction data anomaly-analysis helper with ordinary local file processing and no evidence of hidden execution, exfiltration, persistence, or destructive behavior.

Install dependencies only in a project virtual environment, preferably with pinned versions. Use this skill on project data you intentionally provide, and review any cost-estimate-style output as analytic guidance rather than an authoritative estimate.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:507
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 507
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install pandas numpy scipy

Technical Analysis

The installation command retrieves three third-party packages without fixed versions, package hashes, a lockfile, or an explicitly trusted package index. As a result, the code installed by this command can change over time without any corresponding change to the reviewed Skill.

Package installation may execute package-controlled build or installation logic. If a package release or configured Python package index is compromised, following this instruction could cause unreviewed code to run with the privileges of the user executing pip. Unpinned dependencies also create reproducibility and compatibility risks, although those concerns alone are not necessarily security vulnerabilities.

No evidence was found that the named packages are currently malicious. The risk arises from mutable and insufficiently verified dependency resolution.

Attack Path

  1. A user follows the dependency installation instructions in SKILL.md.
  2. The user runs pip install pandas numpy scipy.
  3. pip resolves the latest compatible releases from the user's configured package index or mirror.
  4. An attacker compromises an upstream release, distribution account, or configured mirror.
  5. The compromised package artifact supplies malicious installation or runtime code.
  6. That code executes on the user's system during installation or when the anomaly detector imports the package.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the account running pip. Depending on that account's permissions and environment, the attacker could access project datasets, modify user-accessible files, steal environment-held credentials, or compromise subsequent analysis results.

The affected scope is normally limited ...[truncated 158 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency manifest with exact version pins, such as:

    text
    pandas==REVIEWED_VERSION
    numpy==REVIEWED_VERSION
    scipy==REVIEWED_VERSION
    
  2. Generate and verify cryptographic hashes for every package and transitive dependency, then install with:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Use a lockfile generated through a dependency-management tool so transitive dependencies are also reproducible.

  4. Configure an explicitly trusted package index or an internally controlled artifact repository rather than relying on an arbitrary user-configured mirror.

  5. Regularly scan locked dependencies for known vulnerabilities and review updates before changing pinned versions.

  6. Install dependencies in an isolated virtual environment using a non-privileged account. Do not run the installation command as root or with elevated permissions.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions expand the skill’s behavior from anomaly detection into creating cost estimates, which is outside the stated purpose and can cause scope confusion. In an agent setting, this kind of mismatch can lead the model to perform unintended financial analysis or generate authoritative-sounding estimates without the controls, assumptions, or validation expected for estimating workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.