Back to skill

Security audit

VMamba Env Doctor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward VMamba environment setup guide; its package installs and build commands are expected for that purpose, though users should run them in a clean, non-privileged environment.

Install only in a fresh VMamba conda environment, confirm it is active before running the commands, avoid root or sudo for pip and build steps, and build selective_scan only from a trusted VMamba repository checkout.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:52
Finding

Unpinned Third-Party Installer Creates Supply-Chain Exposure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:52-58
Mirrored Locations: README.md:63-68, README-CN.md:63-68
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Complete Code Snippet:

bash
# 5. Install OpenMMLab packages
python -m pip install --upgrade pip
python -m pip install setuptools==81.0.0 wheel
python -m pip install -U openmim
mim install mmengine==0.10.1
mim install mmcv==2.1.0
python -m pip install mmsegmentation==1.2.2 mmdet==3.3.0 mmpretrain==1.2.0

Technical Analysis

The instructions install or upgrade openmim without specifying an exact version or verifying an integrity hash:

bash
python -m pip install -U openmim

Consequently, the package selected at installation time can differ from the package that existed when the Skill was reviewed. Python package installation can execute package build hooks and other installation logic with the privileges of the invoking user.

The subsequently invoked mim executable is trusted to resolve and install additional packages. Although several downstream package versions are pinned, their artifacts are not protected by hashes, and the source index is not explicitly constrained.

No evidence indicates that openmim or the named packages are currently malicious. The issue is the absence of controls that make third-party dependency retrieval reproducible and resistant to repository compromise, package takeover, or unexpected upstream changes.

Attack Path

  1. An upstream package release, package repository, maintainer account, or dependency is compromised.
  2. The user follows the Skill and runs python -m pip install -U openmim.
  3. Pip retrieves the latest package accepted by its resolver rather than a reviewed, immutable artifact.
  4. Malicious installation or build logic executes under the invoking user's account.
  5. The installed mim command can then run or retrieve ...[truncated 870 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin openmim to a specifically reviewed version rather than using -U:

    bash
    python -m pip install openmim==<reviewed-version>
    
  2. Publish a hash-locked requirements file and install with hash verification:

    bash
    python -m pip install --require-hashes -r requirements.lock
    
  3. Pin all direct and transitive dependencies to tested versions.

  4. Explicitly use an approved package index and disable unintended extra indexes.

  5. Verify downloaded wheel hashes or package signatures before installation.

  6. Run dependency installation in a disposable, non-privileged environment.

  7. Document the date, source, and hashes of the dependency set described as “verified.”

  8. Avoid running package installation commands with sudo or from an administrative shell.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:65
Finding

Unverified Local Build Code Is Executed Without Build Isolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:65-70
Mirrored Locations: README.md:75-79, README-CN.md:75-79
Vulnerability Type: Unsafe execution of local package build hooks
Risk Level: Medium

Complete Code Snippet:

bash
# 7. Compile selective_scan with gcc-11
# (Ensure gcc-11 and g++-11 are installed: sudo apt install gcc-11 g++-11)
export CC=gcc-11
export CXX=g++-11
cd kernels/selective_scan
pip install . --no-build-isolation

Technical Analysis

The command below instructs pip to build and install whichever Python project exists in the current kernels/selective_scan directory:

bash
pip install . --no-build-isolation

Python package build metadata and backend hooks can execute arbitrary code during installation. The Skill does not verify that the current directory belongs to the official VMamba repository, that the checkout is at a trusted commit, or that relevant build files have not been modified.

The --no-build-isolation option causes the build to use the active environment rather than an isolated build environment. This increases exposure of installed packages and environment state to the build process and can also make dependency resolution less reproducible.

Build isolation is not a complete sandbox and would not by itself prevent malicious build hooks from running. The primary risk is executing unverified local repository code; disabling isolation further weakens environmental separation.

Attack Path

  1. An attacker supplies a modified VMamba checkout, compromises an existing working tree, or convinces the user to run the instructions from an unintended directory.
  2. The attacker adds malicious behavior to package build files or the selected build backend under kernels/selective_scan.
  3. The user follows the Skill, changes into that directory, and runs pip install . --no-build-isolation.
  4. Pip invokes attacker-controlled build or insta ...[truncated 923 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require users to obtain VMamba from its documented official repository.

  2. Pin the source checkout to a reviewed release tag or immutable commit hash.

  3. Provide commands to verify the repository remote and commit before building:

    bash
    git remote -v
    git rev-parse HEAD
    git status --short
    
  4. Validate the expected hashes of build metadata and relevant native source files.

  5. Remove --no-build-isolation unless it is strictly required. If required, explain the risk and document the exact build dependencies that must already be installed.

  6. Build the extension in a disposable container or dedicated non-privileged environment with no secrets mounted.

  7. Prefer a reviewed, reproducible binary artifact where practical.

  8. Never run the package build with sudo or from a root shell.

  9. Separate the privileged installation of system compilers from the unprivileged compilation of repository code.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README includes copy-and-execute environment modification commands, including package uninstallation, without warning users that these steps will remove existing packages from the active environment. In a setup skill that users may follow verbatim, this can cause accidental disruption of a shared or mis-selected conda environment and make recovery harder, especially for less experienced users.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
python -m pip install --no-cache-dir opencv-python-headless==4.10.0.84

# 7. Compile selective_scan with gcc-11
# (Ensure gcc-11 and g++-11 are installed: sudo apt install gcc-11 g++-11)
export CC=gcc-11
export CXX=g++-11
cd kernels/selective_scan

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README provides copy-pasteable shell commands that create a new conda environment, install and uninstall packages, and modify compiler environment variables, but it does not explicitly warn users that these commands will change their local environment. Although these actions are part of the skill's setup purpose, the package uninstall step and broad environment modifications would benefit from a clear caution before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file instructs the user to create a new conda environment, install multiple packages, and uninstall existing OpenCV packages, which can change the user's system or environment state. Although these actions are part of the skill's purpose, the document does not explicitly warn users that the commands will modify their environment and remove packages.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.