Back to skill

Security audit

CSV Stats Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it reads a user-specified CSV file and reports basic statistics without modifying files.

Install only if you are comfortable with uv downloading pandas when the skill runs. Use it on CSV files you trust, or run it in a constrained environment if analyzing untrusted CSVs, because crafted headers could affect terminal display and the runtime dependency is not pinned.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned pandas Dependency Resolved at Runtime

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 24
Vulnerability Type: Unpinned third-party runtime dependency
Risk Level: Medium

Vulnerable Code Snippet:

text
- Run it with: uv run --with pandas {baseDir}/analyzer.py [csv-path]

Technical Analysis

The documented execution command instructs uv to resolve and install pandas without an exact version or verified package hashes. Consequently, the project does not fully determine which third-party code will execute. The resolved version can change over time based on package-index state and resolver behavior.

This creates a supply-chain exposure: a compromised package release, package index, or transitive dependency could introduce arbitrary code. Python packages may execute code during installation or when imported by analyzer.py.

Attack Path

  1. An attacker compromises a future pandas release, one of its resolved dependencies, or the configured package source.
  2. A user invokes the skill according to the documented command.
  3. uv resolves the unpinned dependency from the package source and downloads or installs the affected release.
  4. The malicious dependency code executes during installation or when import pandas as pd is evaluated.
  5. The code operates with the permissions of the user running the skill.

Impact Assessment

Successful exploitation could execute arbitrary code with the invoking user's privileges. This may permit access to files, environment variables, credentials, and network resources available to that user. The scope is limited by the runtime account's operating-system permissions and any sandboxing applied by the host environment.

Remediation
View remediation

Remediation Suggestions

  • Pin pandas and all transitive dependencies to reviewed, exact versions in a lockfile.
  • Require cryptographic hashes for downloaded distributions where supported.
  • Install dependencies during a controlled provisioning step rather than resolving them on every invocation.
  • Configure uv to use a trusted package index and prevent fallback to untrusted sources.
  • Regularly scan locked dependencies for known vulnerabilities and review lockfile changes before deployment.
  • Run the analyzer with minimal filesystem and network permissions.

T09 · Insecure Skill Coding Practices

Note
Location
analyzer.py:15
Finding

Terminal Control-Sequence Injection Through CSV Column Names

Content
View full analysis

Vulnerability Details

File Location: analyzer.py, lines 15–21
Vulnerability Type: Unsanitized attacker-controlled terminal output
Risk Level: Low

Vulnerable Code Snippet:

python
print(f"📋 Columns: {list(df.columns)}")
      
numeric_cols = df.select_dtypes(include=['number']).columns
if len(numeric_cols) > 0:
    print("\n📈 Numeric Column Stats:")
    for col in numeric_cols:
        print(f"   • {col}: Avg = {df[col].mean():.2f} | Min = {df[col].min()} | Max = {df[col].max()}")

Technical Analysis

CSV column names originate from the analyzed file and are therefore untrusted. The script interpolates these names directly into terminal output without removing ANSI escape sequences or other control characters.

A crafted header can contain terminal commands that alter colors, clear or overwrite displayed content, create deceptive hyperlinks, or otherwise manipulate terminal presentation. Python's list representation may escape some ordinary control characters in the line at line 15, but line 21 interpolates each numeric column name directly and provides a straightforward output path for embedded control sequences.

Attack Path

  1. An attacker creates a CSV whose numeric-column header contains ANSI or other terminal control sequences.
  2. The attacker causes a user to analyze that CSV with the skill.
  3. pandas.read_csv accepts the malicious text as a column name.
  4. The column is identified as numeric and interpolated directly into the output at line 21.
  5. A compatible terminal interprets the control sequence, causing attacker-selected display manipulation.

Impact Assessment

Exploitation can spoof or conceal analyzer output, display misleading messages or links, and modify terminal presentation state. It does not, based on the reviewed code alone, grant filesystem privileges or direct arbitrary command execution. The effect is primarily confined to the terminal or out ...[truncated 42 chars]

Remediation
View remediation

Remediation Suggestions

  • Sanitize every column name before displaying it.
  • Remove or visibly escape C0/C1 control characters, the escape character, and ANSI control-sequence patterns.
  • Use a dedicated safe-output function consistently for both the complete column list and individual statistics.
  • Consider rendering untrusted names with an escaped representation such as unicode_escape, while preserving a separate original value for DataFrame indexing.
  • Add tests using headers containing ANSI color codes, carriage returns, backspaces, bidirectional Unicode controls, and terminal hyperlinks.
  • If output is rendered as Markdown or HTML, also apply the escaping rules required by that renderer.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.