Back to skill

Security audit

Airtable w/Python

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Airtable helper that is aligned with its purpose, though it can modify or delete Airtable data when given a token.

Install only in an isolated environment if possible, use an Airtable token scoped to the specific base and permissions needed, test on a non-production base first, and double-check record/table IDs before running delete or schema-changing commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:14-18
Vulnerability Type: Unpinned package installation and insufficient supply-chain verification
Risk Level: Medium

Vulnerable Code

yaml
install:
  - id: pydantic-airtable
    kind: pip
    package: pydantic-airtable
    label: Install pydantic-airtable

The same unpinned installation is also documented at SKILL.md:26:

bash
pip install pydantic-airtable

Technical Analysis

The skill installs pydantic-airtable without specifying an exact reviewed version, a cryptographic hash, or a locked dependency set. Consequently, each installation resolves whichever version the configured pip index currently serves, including its transitive dependencies.

The bundled scripts import this package and pass an Airtable access token into its objects. A compromised package release, compromised package index, or malicious dependency resolved through an untrusted index could execute arbitrary Python code during installation or import. Version drift may also introduce security regressions after the skill itself has been reviewed.

Attack Path

  1. An attacker compromises the upstream package, one of its transitive dependencies, or a package index used by the environment.
  2. The attacker publishes or substitutes a malicious version that still satisfies the unbounded package requirement.
  3. A user or agent follows the skill installation configuration or runs pip install pydantic-airtable.
  4. pip retrieves and installs the attacker-controlled release.
  5. Malicious code executes during package installation or when a bundled script imports pydantic_airtable.
  6. When the scripts run, the malicious dependency can read the process environment, including AIRTABLE_ACCESS_TOKEN and AIRTABLE_BASE_ID, and can access data available to that token.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the account running pip or the scripts ...[truncated 347 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin pydantic-airtable to an exact, reviewed version in both the installation metadata and documentation.
  2. Maintain a lock file that pins all transitive dependencies.
  3. Require cryptographic hashes for every resolved artifact, such as through pip install --require-hashes -r requirements.txt.
  4. Retrieve packages only from an explicitly configured and trusted index; disable unintended supplemental indexes.
  5. Review the package source and dependency changes before updating the pinned version.
  6. Install and execute the dependency in a dedicated virtual environment or container under a nonprivileged account.
  7. Continue using least-privilege Airtable tokens and restrict outbound network access where operationally feasible.
  8. Add automated dependency vulnerability and provenance checks to the release process.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
Keep `SKILL.md` focused on workflow. Read `references/api-surface.md` only when exact method names or signatures matter.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares capabilities that rely on environment variables and local file reads, but it does not define an explicit tool scope such as permissions or allowed-tools. This weakens isolation and reviewability because an agent may access sensitive credentials or local files without a clearly constrained contract, which is especially relevant here since the skill explicitly uses Airtable tokens and supports loading JSON from disk and importing local Python modules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents methods such as create, update, delete, create_table, delete_base, delete_table, and sync operations, but provides no warning that these actions can modify or permanently remove remote Airtable data and schema. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script supports a destructive delete action that removes an Airtable record, but the code provides no confirmation prompt, warning message, or other user-facing disclosure at the point of execution. Although the CLI description mentions managing records, it does not specifically warn that a delete action is irreversible or destructive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script exposes a direct table-deletion operation with no confirmation prompt, dry-run mode, or explicit warning before invoking manager.delete_table(...). In an agent or automation context, a malformed prompt, operator mistake, or unintended tool invocation could irreversibly delete Airtable tables and cause data loss.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/model_ops.py (reported line 20)May include surrounding context.

python
module = importlib.util.module_from_spec(spec)
    spec.loader.exec_module(module)
    try:
        return getattr(module, class_name)
    except AttributeError as exc:
        raise SystemExit(f"Class {class_name} not found in {module_path}") from exc

Static analysis

No suspicious patterns detected.