Back to skill

Security audit

Response Tone Polisher

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local writing helper, with manageable cautions around unnecessary package installation and saving confidential review text to disk.

Before installing, consider removing the requirements.txt dependencies or using an isolated environment, since dataclasses and enum should normally come from Python itself. When using the tool, save outputs only in private, approved locations because response letters may contain confidential manuscript or peer-review material.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unnecessary and Unpinned Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2
Vulnerability Type: Unpinned and unnecessary third-party dependencies
Risk Level: Medium

Vulnerable Code

text
dataclasses
enum

The installation instruction appears at SKILL.md:235-239:

markdown
## Prerequisites

```bash
pip install -r requirements.txt
text

### Technical Analysis

The project instructs users to install the packages `dataclasses` and `enum` without version constraints or integrity hashes. However, `scripts/main.py` uses Python 3 and imports `dataclasses` and `enum`, both of which are included in the Python standard library on supported Python versions.

Installing external distributions with these names is unnecessary and expands the software supply-chain attack surface. Because the dependencies are not pinned or hash-verified, package resolution may retrieve mutable releases whose contents were not reviewed with this project. Python package installation may execute package build or installation logic.

No evidence confirms that the current package releases are malicious. The finding concerns the avoidable and insecure dependency-installation design.

### Attack Path

1. A user follows the prerequisite instructions in `SKILL.md`.
2. The user runs `pip install -r requirements.txt`.
3. Pip resolves the unpinned `dataclasses` and `enum` distributions from the configured package index.
4. If an upstream release, configured index, or dependency-resolution path is compromised, attacker-controlled package build or installation logic executes.
5. That code runs with the privileges of the user or automation account performing the installation.

### Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing account. The resulting scope may include access to that account's readable files, environment variables, project data, and writable resources. If installation i
...[truncated 266 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both entries from requirements.txt; the implementation can use the Python standard-library modules directly.
  2. Remove or revise the pip install -r requirements.txt prerequisite when no external dependencies remain.
  3. Explicitly document the minimum supported Python version.
  4. If support for a legacy Python version genuinely requires a backport, use the correct conditional dependency marker and pin an audited version.
  5. For any future third-party dependencies, use exact version pins and hash verification, for example with pip install --require-hashes.
  6. Audit dependencies in CI and obtain packages only from a trusted, controlled package index.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents local script execution plus file read/write behavior, but it does not declare any explicit tool scope such as allowed tools or constrained permissions. In an agent ecosystem, this can cause the runtime to grant broader-than-expected filesystem capabilities, increasing the risk of unintended file access, overwrite, or path traversal if the implementation is loose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The tool may persist polished responses, suggestions, and derived metadata to disk without clearly warning the user that manuscript and peer-review content may be sensitive or confidential. In the academic review context, this increases the chance of unintentionally storing confidential material in unsafe locations, shared folders, or version-controlled directories.

Content

No source excerpt is available for this finding.

Tainted flow: 'save' from input (line 543, user input) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/main.py (reported line 552)May include surrounding context.

python
"improvements": result.improvements,
            "suggestions": result.suggestions
        }
        with open(save, 'w') as f:
            json.dump(output, f, indent=2)
        print(f"✅ Saved to {save}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command-line --output path causes potentially sensitive peer-review content and metadata to be written to disk with no disclosure or guardrails. Because this skill is specifically designed to process reviewer comments and draft rebuttals, the saved data is likely to include confidential pre-publication material whose unintended persistence can create privacy or confidentiality exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The statement "Best for English-language responses" introduces a language constraint in the skill's natural-language documentation. Because the file does not offer an explicit language choice or user opt-in, this can be read as a locale/language preference baked into the skill behavior.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/tone_patterns.md (reported line 199)May include surrounding context.

md
Don't promise changes you won't make.

❌ "We will conduct additional experiments..." (if you won't)
✅ "We respectfully note that additional experiments are beyond the scope..."

## Quick Reference: Severity Levels

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
dataclasses
enum

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
dataclasses
enum

Static analysis

No suspicious patterns detected.