Back to skill

Security audit

Data Profiler

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local construction-data profiling helper, with some normal privacy and dependency hygiene cautions but no evidence of hidden or malicious behavior.

Install and run this in an isolated Python environment, pin dependencies if reproducibility matters, and avoid exporting or sharing generated profiles unless you are comfortable with column names, top values, and summary statistics from the source data being included.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:477
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 477–480
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install pandas numpy

Technical Analysis

The installation command retrieves mutable versions of pandas, numpy, and their transitive dependencies from the package index configured for pip. No exact versions, cryptographic hashes, lock file, or trusted-index restrictions are specified.

Consequently, two installations performed at different times may resolve to different dependency sets. If a package release or configured package index is compromised, or if an unexpected future release is selected, unreviewed code could be installed and executed with the user's privileges. The audit found no evidence that these package names are themselves malicious; the issue is the absence of dependency integrity and reproducibility controls.

Attack Path

  1. An attacker compromises a selected package release, a transitive dependency, or a package index used by the environment.
  2. A user follows the documented dependency installation command.
  3. pip resolves the current mutable package versions from its configured index without validating them against project-approved hashes.
  4. The compromised package is installed.
  5. Malicious code may execute during installation, import, or subsequent data-profiling operations.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user or automation account performing the installation or running the profiler. This could expose construction datasets and other files accessible to that account, alter generated reports, or compromise the associated Python environment. The scope is limited by the installing user's operating-system permissions and environmental isolation.

Remediation
View remediation

Remediation Suggestions

  1. Move dependencies into a reviewed requirements or lock file and pin exact versions.
  2. Pin all transitive dependencies rather than only direct dependencies.
  3. Generate and verify cryptographic hashes, then install with a command such as:
bash
python -m pip install --require-hashes -r requirements.txt
  1. Use an approved package index or internal mirror and explicitly configure trusted sources.
  2. Run dependency vulnerability and provenance checks in CI before publishing updates.
  3. Install and execute the profiler in an isolated virtual environment or container with least-privilege filesystem access.
  4. Establish a controlled update process that reviews, tests, and regenerates dependency locks and hashes.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example exports a profiling result to JSON even though the generated profile can include top values and column-level summaries derived directly from source data. In a data-profiling context, those top values may contain sensitive or regulated information such as names, emails, phone numbers, IDs, or financial values, and the skill does not warn users or apply redaction before persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction 'When the user asks to assist with construction project tasks' is broad and lacks clear trigger boundaries or exclusions. This could overlap with many ordinary construction-related requests and does not specify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.