Back to skill

Security audit

Speedtest.net

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently runs a local Speedtest.net bandwidth test and discloses its network use, with some ordinary setup and privacy cautions.

Install only if you are comfortable running a network speed test that contacts external Speedtest servers and may reveal IP/ISP details in JSON output. Prefer installing speedtest-cli in an isolated, unprivileged environment and pinning the package version if you need reproducible or higher-assurance installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
setup.md:14
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: setup.md, lines 14–17
Vulnerability Type: Unpinned dependency installed from the active Python package index
Risk Level: Medium

Vulnerable Code:

markdown
### Option 1: pip

```bash
pip3 install speedtest-cli
text

The same unpinned installation command is repeated as troubleshooting guidance at `setup.md`, lines 41–44.

### Technical Analysis

The setup documentation instructs users to install `speedtest-cli` without specifying an exact reviewed version or validating package hashes. Although the requirements table states that version 2.x is expected, the installation command does not enforce that constraint and may resolve any version offered by the configured package index.

Python package installation can execute package-controlled build or installation logic. Consequently, compromise of the package publisher, package index, dependency resolution path, or local pip index configuration could cause attacker-controlled code to execute during installation. The absence of hash verification also prevents pip from detecting an artifact that differs from the reviewed release.

This is a supply-chain weakness rather than evidence that the currently named package is malicious.

### Attack Path

1. An attacker compromises the package publisher, distribution account, configured package index, or network/dependency resolution environment.
2. The attacker makes a malicious or substituted `speedtest-cli` distribution available through the index used by pip.
3. A user follows the documented `pip3 install speedtest-cli` instruction.
4. Pip resolves and downloads the unpinned artifact without checking a project-supplied cryptographic hash.
5. Attacker-controlled installation or build logic executes with the privileges of the user running pip.
6. The installed executable may subsequently execute additional attacker-controlled behavior whenever the skill invokes `speedtes
...[truncated 519 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin speedtest-cli to an exact, reviewed version rather than accepting any available release.

  2. Record cryptographic hashes in a locked requirements file, for example:

    text
    speedtest-cli==REVIEWED_VERSION \
        --hash=sha256:REVIEWED_DISTRIBUTION_HASH
    
  3. Install using hash enforcement:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Review and update the pinned version and hashes through a controlled dependency-update process.

  5. Recommend installation in an isolated virtual environment under an unprivileged account.

  6. Specify the trusted package index explicitly where appropriate and avoid unreviewed additional indexes.

  7. Update the troubleshooting section so it does not reintroduce the unpinned installation command.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (6)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · setup.md (reported line 23)May include surrounding context.

Option 2: apt (Debian/Ubuntu/Kali)

bash
sudo apt update && sudo apt install speedtest-cli

Note: apt versions may lag behind pip.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents execution of a local Python script and therefore implies shell/code execution capability, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates a policy gap where an agent may invoke shell access more broadly than intended, reducing reviewability and increasing the chance of unintended command execution in environments that rely on manifest-declared restrictions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common conversational requests like 'check speed' or 'check internet speed,' which can cause the skill to activate in unintended contexts. Because the skill performs a real network test that consumes bandwidth and contacts external servers, accidental invocation can lead to unnecessary network activity, privacy-relevant disclosures such as IP/ISP in JSON output, or disruption on constrained hosts.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/speedtest.py (reported line 32)May include surrounding context.

python
if server:
        cmd.extend(["--server", str(server)])

    proc = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout + 10)

    if proc.returncode != 0:
        print(f"speedtest failed (exit {proc.returncode}):\n{proc.stderr}", file=sys.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/speedtest.py (reported line 48)May include surrounding context.

python
if server:
        cmd.extend(["--server", str(server)])

    proc = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout + 10)

    if proc.returncode != 0:
        print(f"speedtest failed (exit {proc.returncode}):\n{proc.stderr}", file=sys.stderr)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.md (reported line 23)May include surrounding context.

Option 2: apt (Debian/Ubuntu/Kali)

bash
sudo apt update && sudo apt install speedtest-cli

Note: apt versions may lag behind pip.

Static analysis

No suspicious patterns detected.