Back to skill

Security audit

Grasshopper Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for generating Grasshopper files, but it can create executable GhPython content and overwrite local files without enough user control or warning.

Review this skill carefully before installing. Use it only when you intend to generate Grasshopper files, choose a safe output directory, avoid overwriting existing files, and inspect any embedded GhPython source before opening the generated .ghx in Rhino/Grasshopper.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ghx_generator.py:346
Finding

Unrestricted Executable GhPython Code Embedded in Generated GHX Files

Content
View full analysis
ComponentRef: """Add a GhPython Script component with custom Python code. Code has access to input variables by name. Assign `a = result` for output. Full Rhino.Geometry API is available. """ inputs = inputs or [] outputs = outputs or [] if x is None: x = self._auto_x self._auto_x += 200 if y is None: y = 50 instance_guid = _new_guid() comp_guid = self._resolve_guid("GhPython Script") or _new_guid() obj = _chunk("Object") obj.append(_wrap_items([ _item("GUID", comp_guid, "gh_guid", TC_GUID), _item("Name", "GhPython Script", "gh_string", TC_STRING), ])) container = _chunk("Container") container.append(_wrap_items([ _item("CodeInput", code, "gh_string", TC_STRING), _item("Description", "A Python script component", "gh_string", TC_STRING), _item("InstanceGuid", instance_guid, "gh_guid", TC_GUID), _item("Name", "GhPython Script", "gh_string", TC_STRING), _item("NickName", nickname, "gh_string", TC_STRING), ])) ``` ### Technical Analysis The `add_python` method accepts arbitrary caller-provided Python source in the `code` argument and inserts it directly into the `CodeInput` field of a GhPython component. No validation, import restrictions, API allowlist, static analysis, or user-approval boundary is applied. Embedding custom scripts is an advertised feature, but the implementation does not limit scripts to geometry operations. A generated GHX file is therefore an executable documen ...[truncated 1599 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ghx_generator.py:575
Finding

Arbitrary File Overwrite Through Unrestricted Output Path

Content
View full analysis
str: """Save .ghx file to disk. Returns the path.""" with open(path, "w", encoding="utf-8") as f: f.write(self.to_xml_string()) return path ``` The path is also exposed directly through the command-line interface: ```python parser.add_argument("-o", "--output", default="/tmp/demo_cylinder.ghx", help="Output .ghx path") ``` ```python gen = _demo() path = gen.save(args.output) ``` ### Technical Analysis The `save` method accepts an arbitrary path and opens it in `w` mode. Python's write mode truncates an existing file before writing the generated XML. The implementation does not: - Restrict output to an approved directory. - Require a `.ghx` extension. - Reject absolute paths or parent-directory traversal. - Detect symbolic links. - Use exclusive creation. - Ask for confirmation before replacing an existing file. The CLI passes the user-controlled `--output` value directly to this method. The same condition applies to callers of the public library API. In an agent context, an attacker could attempt to influence the output path through untrusted task instructions. ### Attack Path 1. An attacker or untrusted instruction supplies an output path that identifies an existing writable file. 2. The agent invokes the CLI with `--output` or calls `save(path)` using that value. 3. `open(path, "w")` follows normal path resolution and opens the target for writing. 4. If the target already exists, its previous contents are truncated. 5. The generated GHX XML replaces the target file. ### Impact Assessment Exploitation can destroy or corrupt any file writable by the account running the generator. The exact scope is limited by that account's filesystem permissions. Possible consequences ...[truncated 311 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill includes code and explicitly saves an output file (gen.save("output.ghx")), but it declares no permissions or allowed-tools scope. That creates an authorization gap where the skill's effective file-write behavior is undocumented and potentially unconstrained, increasing the risk of unintended file creation or overwriting if invoked in an agent environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad phrases such as grasshopper, GH file, and when user wants a .ghx file, which can cause the skill to activate in loosely related contexts. Overbroad activation increases the chance the agent selects a file-writing/code-generating skill unnecessarily, exposing users to unintended side effects or confusing tool invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents file creation via gen.save("output.ghx"), which affects user data on disk. The description does not include any warning or note about creating or overwriting files, so users are not clearly informed of this side effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.