Back to skill

Security audit

tra-extract-text

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for extracting text from user-provided web URLs, with ordinary dependency and network-use cautions but no hidden or destructive behavior.

Install in a virtual environment where possible, consider pinning and reviewing the trafilatura package version, and avoid giving the skill internal, private, or sensitive URLs unless you intend the local CLI to fetch them over the network.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–14
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## Installation

```bash
pip install trafilatura
text

### Technical Analysis

The installation command retrieves and installs the latest available version of the third-party `trafilatura` package without specifying a reviewed version or validating an integrity hash. Consequently, the dependency resolved at installation time may differ from the version assessed during the Skill audit.

Although the package name does not appear to be a typographical imitation, the absence of version pinning and artifact verification creates a supply-chain risk. A compromised package release, distribution account, dependency, or package index could introduce malicious code. Python package installation may execute build-related code, while subsequent invocation of the installed CLI executes package code with the invoking user's privileges.

### Attack Path

1. An attacker compromises the package's release process, publishing account, distribution infrastructure, or a transitive dependency.
2. The attacker publishes a malicious release under the expected package name or causes package resolution to return a malicious artifact.
3. A user follows the documented `pip install trafilatura` instruction.
4. `pip` resolves the unpinned dependency to the attacker-controlled release.
5. Malicious code executes during package installation, package loading, or later use of the `trafilatura` CLI.

### Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user running `pip` or the CLI. Depending on those privileges, the malicious package could read or alter accessible files, access environment variables and credentials, initiate network connections, or tamper with the user's Python environment. The reviewed project itself con
...[truncated 176 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin trafilatura to a specifically reviewed version instead of installing the latest release implicitly.
  • Record dependencies in a lock file or requirements file that includes cryptographic hashes.
  • Install with hash enforcement, such as pip install --require-hashes -r requirements.txt.
  • Review and pin transitive dependencies where feasible.
  • Use the official Python Package Index or an approved internal package mirror explicitly.
  • Perform installation in an isolated virtual environment under a non-privileged account.
  • Add a controlled dependency-update process that reviews new versions before changing the pin.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to fetch arbitrary URLs with trafilatura but does not warn that this causes outbound network requests to third-party destinations. That omission can expose user-supplied targets, internal URLs, or sensitive browsing intentions to external services and infrastructure, especially if the skill is used in automated or enterprise environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.