Back to skill

Security audit

Python Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Python automation toolkit, but its bundled scripts have safety gaps that could move or overwrite local files or create risky spreadsheet output.

Review this skill before installing if you plan to use the bundled scripts on important folders or untrusted CSV files. Run file-renaming operations only on test copies or with dry-run first, avoid broad directories, use pinned dependencies in a virtual environment, and sanitize CSV values before converting untrusted data to Excel.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rename_batch.py:39
Finding

Batch Rename Destination Path Escape

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rename_batch.py:17
Finding

Duplicate Rename Destinations Can Cause Data Loss

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/csv_to_excel.py:22
Finding

CSV-to-Excel Formula Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly includes batch file processing patterns that read and overwrite files recursively, but the description and guidance do not warn users about destructive behavior, scope control, backups, or dry-run validation. In an automation skill focused on bulk file and system tasks, this omission increases the chance of unintended mass modification or data loss from overbroad paths or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown reference includes pd.read_html("https://table-page.com"), which causes a network request to an external site, but the document does not warn that the example fetches remote content. For markdown files, SQP-2 applies when behaviour affecting privacy or system/network activity is described without disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes code that generates and saves a PDF to "output.pdf" via reportlab, which is a file-writing operation. The surrounding documentation does not include any warning that running the example will create or potentially overwrite a local file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The fpdf2 example calls pdf.output("output.pdf"), which writes a file to disk. The markdown presents this as a simple example but does not warn users about the file creation or possible overwrite of an existing file with the same name.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The merge/split section ends with writer.write("merged.pdf"), which creates a new file on disk. There is no accompanying note in the markdown warning that executing the example will write an output file and could overwrite an existing file if adapted carelessly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.