Back to skill

Security audit

SenseCraft AI Model Hub

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and purpose-aligned, but its optional demo can install Python packages, download models, open the webcam, and save local files.

Install only if you are comfortable with a skill that can query SenseCraft, write model indexes/manifests/downloads, and optionally run a local webcam demo. Review commands before running the demo, use a dedicated directory or virtual environment, avoid opening CSV exports in spreadsheet software unless sanitized, and treat downloaded models as untrusted until verified.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
scripts/setup_local_demo_env.sh:21
Finding

Unpinned Third-Party Dependencies Allow Supply-Chain Code Execution

Content
View full analysis

Vulnerability Details

File Location: scripts/setup_local_demo_env.sh:21-22
Additional Location: references/local-webcam-demo.md:41-42
Vulnerability Type: Unpinned and integrity-unverified package installation
Risk Level: Medium

Vulnerable Code:

bash
python -m pip install --upgrade pip setuptools wheel
python -m pip install numpy opencv-python pillow ai-edge-litert

Technical Analysis

The setup script installs the latest available versions of several packages and their transitive dependencies from the configured Python package index. It does not use exact version constraints, a lockfile, package hashes, or repository restrictions.

Python package installation can execute package build-system code. Installed packages also execute code when imported by the webcam application. Consequently, a compromised package release, compromised transitive dependency, dependency-confusion condition in a custom package-index configuration, or future malicious update could execute code under the account running the setup script.

Upgrading pip, setuptools, and wheel without pinning also changes the build toolchain during installation, making the environment difficult to reproduce or audit.

Attack Path

  1. An attacker compromises one of the named packages, one of its transitive dependencies, or a package index used by the victim.
  2. The attacker publishes a malicious version that satisfies the unconstrained dependency request.
  3. The user follows the documented setup process and runs scripts/setup_local_demo_env.sh.
  4. pip resolves and installs the attacker-controlled release.
  5. Malicious build hooks execute during installation, or malicious runtime code executes when the webcam script imports the installed package.

Impact Assessment

Malicious package code would execute with the privileges of the user running the setup command. It could access files, environment variables, came ...[truncated 207 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed version in a requirements file.
  2. Generate a complete lockfile that also pins transitive dependencies.
  3. Record and enforce package hashes, for example:
    bash
    python -m pip install --require-hashes -r requirements.lock
    
  4. Pin packaging tools instead of upgrading them to unrestricted latest versions.
  5. Explicitly configure the trusted package index and disable unintended extra indexes.
  6. Add automated dependency vulnerability and provenance scanning.
  7. Update references/local-webcam-demo.md to use the same locked installation procedure.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sensecraft_models.py:194
Finding

SenseCraft Metadata Can Trigger Spreadsheet Formula Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/sensecraft_models.py:194-201
Vulnerability Type: CSV formula injection
Risk Level: Medium

Vulnerable Code:

python
with open(path, "w", newline="", encoding="utf-8") as f:
    w = csv.DictWriter(f, fieldnames=fieldnames)
    w.writeheader()
    for m in models:
        row = dict(m)
        row["uniform_types"] = json.dumps(row.get("uniform_types") or [], ensure_ascii=False)
        row.pop("raw", None)
        w.writerow({k: row.get(k) for k in fieldnames})

Technical Analysis

Model metadata obtained from the remote SenseCraft API is written directly into CSV cells. Potentially untrusted fields include model names, descriptions, URLs, and other textual metadata.

The Python CSV module correctly handles delimiter quoting, but CSV quoting does not prevent spreadsheet formula evaluation. Spreadsheet applications may interpret a cell beginning with =, +, -, or @ as a formula when the exported file is opened.

If an attacker can publish or alter model metadata, the attacker can place a spreadsheet formula in one of these fields. Depending on the spreadsheet product and its security configuration, the formula could initiate external network requests, disclose data through formula parameters, or invoke dangerous legacy integration features.

Attack Path

  1. An attacker gains the ability to publish or modify a SenseCraft model record.
  2. The attacker sets a metadata field to a formula-like value, such as one beginning with = or @.
  3. A user runs the index --format csv workflow.
  4. The script writes the attacker-controlled value into the CSV without neutralization.
  5. The user opens the exported file in a spreadsheet application.
  6. The spreadsheet evaluates or prompts execution of the embedded formula.

Impact Assessment

The direct impact depends on the spreadsheet application and its security settings. Possible effe ...[truncated 301 chars]

Remediation
View remediation

Remediation Suggestions

  1. Sanitize all textual CSV cells originating from the API.
  2. Prefix cells beginning with =, +, -, @, tab, carriage return, or line feed with an apostrophe or another spreadsheet-safe neutralization character.
  3. Apply sanitization after converting values to strings and before passing them to DictWriter.
  4. Preserve the original unsanitized values only in JSON exports, clearly treating them as untrusted data.
  5. Document that existing CSV exports should not be opened in formula-capable spreadsheet software without sanitization.
  6. Add tests covering formula prefixes, leading whitespace, tabs, and multiline metadata.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sensecraft_models.py:245
Finding

Remote Model Downloads Lack Origin, Size, and Integrity Validation

Content
View full analysis

Vulnerability Details

File Location: scripts/sensecraft_models.py:245-255
Additional Location: scripts/sensecraft_webcam_person_demo.py:45-46
Vulnerability Type: Unbounded and integrity-unverified remote artifact handling
Risk Level: Medium

Vulnerable Code:

python
with http_open(url, timeout=timeout) as resp:
    ext = infer_extension(url, resp.headers)
    out_path = out_path_base if os.path.splitext(out_path_base)[1] else out_path_base + ext
    final_url = resp.geturl()
    content_type = resp.headers.get("Content-Type")
    with open(out_path, "wb") as f:
        while True:
            chunk = resp.read(1024 * 1024)
            if not chunk:
                break
            f.write(chunk)

The downloaded artifact is subsequently loaded by the inference runtime:

python
self.interpreter = Interpreter(model_path=str(model_path))
self.interpreter.allocate_tensors()

Technical Analysis

The downloader trusts the API-provided file_url and automatically follows redirects through urllib.request.urlopen. It does not enforce an HTTPS-only policy, restrict destination hosts, validate the final redirect destination, impose a maximum artifact size, or verify a cryptographic digest or signature.

The response body is streamed until the server closes the connection. A malicious or compromised endpoint can therefore consume all available storage. The file is also written directly to its final path, so an interrupted or failed transfer can leave a partial artifact.

The local demo later passes the downloaded artifact to ai-edge-litert, which includes native model-parsing functionality. No specific parser vulnerability is demonstrated in the audited code, but accepting an unauthenticated artifact unnecessarily exposes that parser to attacker-controlled input.

Attack Path

  1. An attacker compromises the SenseCraft API, modifies a model record, controls an all ...[truncated 1324 chars]
Remediation
View remediation

Remediation Suggestions

  1. Accept only HTTPS download URLs.
  2. Maintain an allowlist of expected artifact hosts and validate every redirect destination.
  3. Reject URLs containing embedded credentials and unexpected ports.
  4. Enforce a configurable maximum download size using both Content-Length and a running byte counter.
  5. Download to a temporary file in the destination directory, flush and validate it, and then atomically rename it.
  6. Obtain trusted SHA-256 digests or signatures from a channel separate from the artifact URL and verify them before use.
  7. Validate the TFLite file structure and expected input/output tensor characteristics before loading it for inference.
  8. Delete partial files when downloads or validation fail.
  9. Record the expected URL, final URL, size, digest, and validation result in the manifest.
  10. Require explicit confirmation before loading artifacts whose origin or integrity cannot be established.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill introduces undeclared local environment provisioning, package installation, and directory creation under the umbrella of a model-library connector. Hidden or under-declared setup behavior is risky because it expands the trust boundary from passive API access to active local system modification.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill introduces undeclared local environment provisioning, package installation, and directory creation under the umbrella of a model-library connector. Hidden or under-declared setup behavior is risky because it expands the trust boundary from passive API access to active local system modification.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill introduces undeclared local environment provisioning, package installation, and directory creation under the umbrella of a model-library connector. Hidden or under-declared setup behavior is risky because it expands the trust boundary from passive API access to active local system modification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code opens the local webcam via OpenCV even though camera access is unrelated to the declared purpose of browsing and downloading models. Unexpected camera access is highly sensitive because it can capture people, surroundings, screens, and other private information, especially when embedded in a skill users do not expect to have sensor access.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope even though its documented workflow requires network access, file reads/writes, and script execution. Without an allowlist or permissions block, an agent may invoke broader capabilities than users expect, increasing the chance of unintended downloads, local file creation, or environment changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes a webcam demo with auto-download and local file creation, but the warning about camera use and filesystem effects appears late and is not presented as an upfront consent gate. Users may trigger privacy-sensitive camera access or unexpected local writes without clearly informed approval.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs live webcam capture and local image persistence even though the skill is described as a model-hub integration for searching, inspecting, exporting, and downloading models. This scope expansion is security-relevant because users and downstream systems may grant the skill broader trust than intended, enabling unexpected access to sensitive visual data from the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Although the program may trigger OS-level camera permissions, it does not provide its own explicit privacy notice that running the demo starts live camera capture. That omission increases the chance of uninformed consent and accidental exposure of personal or environmental data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Pressing s silently saves annotated webcam frames to disk, creating retained copies of potentially sensitive visual data without a strong prior warning. Local retention raises privacy and forensic risk because saved images may persist beyond the session and be accessible to other users, backups, or malware.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

In a markdown skill file, invocation examples should be specific enough to avoid unintended activation. Phrases like "dump the whole public model catalog" and "make me a JSON/CSV index" are fairly broad requests that could overlap with generic data-export intents, and the file does not provide negative examples or tighter boundaries for when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file instructs users to download artifacts with curl -o output.bin and describes emitting manifests plus exporting JSON/CSV indexes, all of which affect local user data. The description does not include any explicit warning that these actions create files on disk or may store model metadata and URLs locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This shell script performs a network-fetching operation to download a model if it is missing. While it prints a status message, it does not clearly disclose that it will make a network request or potentially write files to the models directory before doing so.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The still-image path can write annotated images to an arbitrary user-supplied location, adding local file output behavior not reflected in the stated model-hub-only purpose. While not inherently malicious, undeclared local output increases the attack surface and can surprise users or policy engines that rely on the manifest for capability expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.