Back to skill

Security audit

Python Flow Engine

Security checks for vulnerabilities and agentic risk

Overview

This is a small Python pipeline helper with no credential or network behavior, but users should treat its timeout feature as advisory.

Install only if you are comfortable using a simple in-process Python orchestration helper. Avoid running untrusted node callables, and do not rely on its timeout setting to stop side-effecting work such as file writes, API calls, database updates, or expensive computation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/pipeline.py:203
Finding

Timed-Out Nodes Continue Executing in Background Threads

Content
View full analysis
Any: """Run a function with a timeout using a thread.""" result_container: List = [None] exception_container: List[Optional[Exception]] = [None] def target(): try: result_container[0] = fn(context, data) except Exception as e: exception_container[0] = e thread = threading.Thread(target=target, daemon=True) thread.start() thread.join(timeout) if thread.is_alive(): raise TimeoutError(f"Node execution timed out after {timeout}s") if exception_container[0] is not None: raise exception_container[0] # type: ignore return result_container[0] ``` ### Technical Analysis The timeout implementation waits for the worker thread only for the configured duration. When that duration expires, it raises `TimeoutError`, but Python threads cannot be forcibly terminated and the worker remains alive as a daemon thread. Consequently, the timeout limits how long the caller waits but does not limit how long the node executes. The timed-out callable retains access to the shared `context`, mutable input objects, process permissions, files, network resources, and any other resources available to the host process. The surrounding retry mechanism can make this behavior more dangerous. A timeout is treated as a failed attempt, so a node configured with retries may start another execution while the previous timed-out invocation is still running. Multiple copies can therefore operate concurrently on the same state or external resources. ### Attack Path 1. An attacker supplies, influences, or triggers a pipeline node callable that performs long-running or delayed operations. 2. The node is configured with a ...[truncated 1446 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes very broad terms such as 'flow', 'workflow', and 'pipeline', which can cause the skill to activate in unrelated contexts. Over-broad activation increases the chance an agent will invoke this skill unexpectedly, potentially exposing users to unintended code guidance or execution paths and expanding the attack surface for prompt-routing abuse.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/pipeline_demo.py (reported line 296)May include surrounding context.

python
return "too_late"

    pipe2 = Pipeline()
    n_slow = Node(slow_fn, name="slowpoke", timeout=0.5)
    pipe2.add_node(n_slow)

    print("  --- Slow node with timeout=0.5s ---")

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/pipeline_demo.py (reported line 299)May include surrounding context.

python
return "too_late"

    pipe2 = Pipeline()
    n_slow = Node(slow_fn, name="slowpoke", timeout=0.5)
    pipe2.add_node(n_slow)

    print("  --- Slow node with timeout=0.5s ---")

Static analysis

No suspicious patterns detected.