Back to skill

Security audit

Heliospice

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, coherent astronomy helper, but its setup installs an unpinned external Python package that users should isolate or pin.

Install this only in a virtual environment or container, preferably with a pinned and reviewed `heliospice` version. Expect it to use network/storage for SPICE kernel cache operations, and review upstream package provenance if using it in sensitive environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–12
Vulnerability Type: Unpinned and unverifiable third-party dependency
Risk Level: Medium

Vulnerable Code

markdown
## Setup

```bash
pip install heliospice
text

### Technical Analysis

The setup instructions install the `heliospice` package from the default Python package index without pinning a reviewed version, verifying cryptographic hashes, constraining transitive dependencies, or specifying a trusted package source. Because this project contains only `SKILL.md` and does not include the package implementation or a dependency lock file, the executable code installed by this command cannot be verified from the audited artifact.

An unpinned installation resolves whichever release and transitive dependencies are available at installation time. If the package, its publishing account, the package index, or one of its dependencies is compromised, users following the documented setup process could install attacker-controlled code. This is a supply-chain exposure; the audited file does not itself prove that the current package is malicious.

### Attack Path

1. An attacker compromises the `heliospice` package, its publisher account, or a transitive dependency, or otherwise causes a malicious release to be resolved by pip.
2. A user or automated agent follows the Skill's setup instructions and executes `pip install heliospice`.
3. Pip retrieves the latest matching package and dependencies from its configured index without checking project-supplied hashes or an approved lock file.
4. Malicious package behavior may execute during installation, import, or subsequent invocation of the documented tools.
5. The payload operates with the privileges and environment access of the account running pip or the installed package.

### Impact Assessment

A compromised dependency could execute arbitrary code with the privileges of the installing or invoking
...[truncated 497 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin heliospice to a specific release that has undergone security and provenance review, for example:
    bash
    python -m pip install "heliospice==<reviewed-version>"
    
  2. Generate and publish a lock file containing exact versions for all transitive dependencies.
  3. Require cryptographic hashes, such as through a requirements file used with pip install --require-hashes.
  4. Document the trusted package index explicitly and avoid untrusted or dependency-confusion-prone extra indexes.
  5. Link to the reviewed upstream source and identify the commit or release corresponding to the pinned package.
  6. Install the package in an isolated virtual environment or restricted container under a non-privileged account.
  7. Add automated dependency vulnerability, provenance, and integrity checks before updating the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.