Back to skill

Security audit

Code Hug

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent development workflow assistant, but it asks for broad repository analysis and auto-fix authority without enough scoping, consent, or data-handling detail.

Review this skill carefully before installing on private or production-adjacent repositories. Use it first on a copy or narrow project path, keep auto_fix disabled unless you are ready to review changes, add .code-hug/ to .gitignore if generated analysis should not be committed, and install dependencies in an isolated environment with pinned versions where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:49
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 49
Vulnerability Type: Uncontrolled third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
pip install PyYAML requests python-dotenv

Technical Analysis

The documented installation command retrieves three third-party Python packages without fixed versions, cryptographic hashes, a lockfile, or an explicitly trusted package index. This means the dependencies installed by users can change over time without any corresponding change to the reviewed Skill.

If a package source or future dependency release is compromised, users following this instruction could install attacker-controlled code. Python packages may execute code during installation and subsequently when imported by the Skill or related tooling.

No evidence demonstrates that the named packages are currently malicious. The vulnerability is the unsafe and non-reproducible dependency acquisition process, which leaves the Skill exposed to supply-chain compromise.

Attack Path

  1. An attacker compromises a referenced package, its maintainer account, its distribution infrastructure, or a future package release.
  2. The attacker publishes a malicious version under the expected package name.
  3. A user follows the installation command in SKILL.md.
  4. pip resolves and downloads the uncontrolled package version from its configured index.
  5. Malicious package code executes during installation or when the installed module is imported.
  6. The payload operates with the permissions of the user or automation account running pip or the Skill.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the invoking user's privileges. Depending on that account's access, the attacker could read or modify source code, access environment variables and local credentials, tamper with generated artifacts, or compromise other projects available to ...[truncated 270 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the inline installation command with a reviewed and version-controlled dependency manifest.
  2. Pin every direct and transitive dependency to an exact version.
  3. Record cryptographic hashes and install with pip --require-hashes.
  4. Generate and commit a lockfile using a dependency-locking tool such as pip-tools.
  5. Configure an explicitly trusted package index or an internally controlled package mirror.
  6. Scan locked dependencies for known vulnerabilities before release and on a recurring schedule.
  7. Install dependencies inside an isolated virtual environment or container using a non-privileged account.
  8. Review and deliberately update dependency pins rather than allowing automatic installation of the latest releases.

Example hardened installation approach:

bash
python3 -m venv .venv
. .venv/bin/activate
python3 -m pip install --require-hashes -r requirements.txt

The corresponding requirements.txt should contain exact versions and approved hashes for all direct and transitive dependencies.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file consistently presents headings, examples, and usage guidance in Chinese, but does not indicate that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. This can constitute a language-policy violation when users are not given an explicit choice or opt-in for locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states that comprehensive analysis results are stored in the workspace under .code-hug/, including audit trails, workflow outputs, validation results, and business/technical analysis artifacts, but it does not warn that these materials may contain sensitive source code details, secrets, internal architecture, or business logic. In a development/orchestration skill, this increases the chance of unintentional long-term retention or accidental disclosure of sensitive project data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The business-rule extraction, PRD generation, workflow mapping, and data-model analysis features are designed to mine repository contents for business logic and process information, yet the skill does not warn that these outputs may expose sensitive intellectual property, internal workflows, or regulated data patterns. This increases the risk of oversharing extracted artifacts with external systems, logs, notifications, or broader audiences than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly offers automatic diagnosis and auto-fix capabilities against a user-supplied project_root, but the documentation does not clearly warn that files may be modified, dependencies changed, or build/configuration files rewritten. In an agentic workflow, this can lead to unintended code or environment changes, especially when invoked on real repositories or production-adjacent workspaces.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.