Back to skill

Security audit

Auto Context Manager

Security checks for vulnerabilities and agentic risk

Overview

This is a local project-context helper with disclosed home-directory persistence and an unnecessary unpinned dependency, but I found no hidden data export, privilege escalation, or destructive behavior.

Before installing, review whether you want automatic context detection at session start and whether the skill should influence memory or skill selection. Consider removing or pinning chromadb unless you specifically need future vector matching. Expect local files under ~/.auto-context/.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unnecessary and Unpinned Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1
Vulnerability Type: Unpinned and unused third-party dependency
Risk Level: Medium

Complete Code Snippet:

text
chromadb>=0.4.0

Technical Analysis

The project permits any ChromaDB release from version 0.4.0 onward, without an upper bound, exact version, or integrity hash. Consequently, dependency resolution can select a future release that was not reviewed with this skill. ChromaDB may also introduce additional transitive dependencies whose versions and installation behavior are outside the project's control.

The audited executable code does not import or use ChromaDB. Its current functionality relies only on Python's standard library. Moreover, README.md:104 describes ChromaDB as optional. Including it as an unconditional requirement therefore expands the software supply-chain attack surface without supporting implemented behavior.

This finding does not establish that the current ChromaDB package is malicious. The risk arises from unnecessary installation and unconstrained selection of future direct and transitive package versions.

Attack Path

  1. A user or automated installer processes requirements.txt.
  2. The package resolver selects any available ChromaDB version satisfying >=0.4.0, potentially including an unreviewed future version.
  3. The resolver installs ChromaDB and its transitive dependencies.
  4. If a selected release or transitive package is compromised, malicious installation hooks or runtime code may execute in the installer or application environment.
  5. That code operates with the privileges of the account or service performing the installation or subsequent import.

Impact Assessment

A compromised dependency could execute arbitrary code with the privileges of the installing user or application service. Depending on those privileges, this could permit access to application data, user-accessible files, ...[truncated 322 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove ChromaDB from requirements.txt while the executable code does not use it.
  2. If semantic matching is implemented later, declare ChromaDB as an optional dependency rather than an unconditional runtime requirement.
  3. Pin the dependency to a specifically reviewed version instead of using only a lower bound.
  4. Generate and enforce cryptographic hashes through a locked requirements file or equivalent reproducible dependency-management mechanism.
  5. Review and constrain transitive dependencies, and run automated vulnerability and provenance checks in CI.
  6. Perform dependency installation in an isolated, least-privileged environment.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation guidance is broad enough to trigger the skill at session start or whenever context is merely 'unclear', which can cause unintended invocation and automatic project inference without a strong user signal. In a context-management skill, this can lead to misclassification, unnecessary reading of local project metadata, and incorrect downstream behavior by other skills that trust the selected project context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Triggering on generic 'project keywords' is vague and may match ordinary conversation, causing the skill to infer or switch context based on common terms rather than deliberate user requests. Because this skill influences which memory and related skills are prioritized, a false match can propagate incorrect context and expose unrelated local project information to the agent workflow.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_acm.py (reported line 80)May include surrounding context.

python
os.chdir(os.path.dirname(__file__))

    # Test detect with default project
    result = subprocess.run(
        [sys.executable, "acm.py", "detect", "hello world"],
        capture_output=True, text=True, encoding='utf-8'
    )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_acm.py (reported line 88)May include surrounding context.

python
assert "default" in result.stdout, f"Expected 'default' in output: {result.stdout}"

    # Test list
    result = subprocess.run(
        [sys.executable, "acm.py", "list"],
        capture_output=True, text=True, encoding='utf-8'
    )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_acm.py (reported line 95)May include surrounding context.

python
assert result.returncode == 0, f"CLI list failed: {result.stderr}"

    # Test current
    result = subprocess.run(
        [sys.executable, "acm.py", "current"],
        capture_output=True, text=True, encoding='utf-8'
    )

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that the system auto-initializes by creating ~/.auto-context/ on first use, which is a filesystem write affecting the user's home directory. While this is likely expected behavior, the description does not explicitly warn users about this side effect or note what files will be created.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code automatically creates a persistent data directory and supporting storage under the user's home directory. While file persistence is core to the component's function, the code itself provides no user-facing notice at initialization that local files and directories will be created.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module writes a new projects.json file containing project metadata and timestamps, but there is no confirmation prompt or user-facing warning at the point of creation. For a code file performing persistent file writes, some disclosure should be present unless it is documented elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This helper performs file writes for all project updates, including current project changes and metadata timestamps, but does not emit any user-visible notice. Although persistence is expected for a context manager, the code lacks an explicit warning or disclosure about storing these updates locally.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency is specified as chromadb>=0.4.0, which allows installation of any future version and makes builds non-reproducible. This increases supply-chain risk because a vulnerable or malicious release could be pulled in without review, and it also prevents verifying whether known advisories affect the installed version.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
chromadb>=0.4.0

Unverifiable Dependency: chromadb has 8 known advisory(ies) (CVE-2026-45830 (ChromaDB allows any authenticated users to arbitrarily read, write, update, or d); CVE-2026-45833 (ChromaDB has a code injection vulnerability); CVE-2026-45829 (ChromaDB Python project has a pre-authentication code injection vulnerability) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The manifest references chromadb without pinning to a specific version even though the package has multiple known advisories, including code injection issues. Because the resolved version is unknown at install time, the project may silently pull an affected release, making the dependency choice materially riskier in this skill context.

Content

No source excerpt is available for this finding.