Back to skill

Security audit

smartchart

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward SmartChart CLI query helper with ordinary command and dependency risks, but no hidden persistence, exfiltration, or destructive behavior in the inspected artifacts.

Install SmartChart in a dedicated virtual environment if possible, verify the package source before installing or upgrading, and only use this skill when you intend to query data through your SmartChart CLI environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned SmartChart Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:10 and SKILL.md:79
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Complete Vulnerable Code Snippets:

markdown
- Python has the `smartchart` library installed (`pip install smartchart`)
markdown
- If the `smartchart` command does not exist, instruct the user to run: `pip install smartchart`

Technical Analysis

The installation instructions retrieve the latest available smartchart package without an exact version constraint, cryptographic hash verification, lockfile, or verified source reference. Consequently, the installed artifact can change after this skill has been reviewed.

Python package installation can execute package-controlled build or installation logic. The resulting package also supplies the smartchart command subsequently invoked by the skill. Exploitation therefore depends on a malicious or compromised package release, package ownership compromise, repository compromise, or another supply-chain substitution affecting package resolution.

Attack Path

  1. An attacker compromises the upstream package, its publisher account, or the package distribution path.
  2. The attacker publishes or substitutes a malicious version of smartchart.
  3. A user follows the skill instruction and executes pip install smartchart.
  4. Pip resolves the mutable, unpinned package version and installs it.
  5. Malicious build or installation logic may execute during installation.
  6. Alternatively, the installed package provides a malicious smartchart executable that runs when the skill performs later queries.

Impact Assessment

Malicious installation logic or an altered CLI would execute with the privileges of the user performing the installation or running the command. Potential scope includes access to that user's files, environment variables, application credentials, SmartChart query data, a ...[truncated 271 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact, reviewed version, such as smartchart==X.Y.Z.
  2. Provide a requirements or lock file containing approved cryptographic hashes.
  3. Install with hash enforcement, for example:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Document the expected package publisher and authoritative source repository so users can verify package identity.
  5. Review each new package release before updating the pinned version.
  6. Prefer installation inside a dedicated virtual environment with minimal filesystem and credential access.
  7. Avoid recommending implicit installation of whichever release is latest at execution time.

T08 · Insecure Dependencies

Warning
Location
references/api_reference.md:34
Finding

Unsafe Installation and Upgrade to an Unreviewed Latest Dependency Version

Content
View full analysis

Vulnerability Details

File Location: references/api_reference.md:34-37
Vulnerability Type: Unpinned third-party dependency installation and upgrade
Risk Level: Medium

Complete Vulnerable Code Snippet:

bash
# Install
pip install smartchart

# Upgrade to the latest version
pip install --upgrade smartchart

Technical Analysis

Both commands resolve a mutable package version. The upgrade command is particularly risky because it explicitly replaces an installed version with the latest available release without requiring that release to have been reviewed or approved.

No exact version, package hash, signed artifact policy, lockfile, or trusted index configuration is supplied. A dependency release published after the audit can therefore introduce new executable behavior while the documentation remains unchanged.

This is a supply-chain risk rather than evidence that the current smartchart package is malicious. Successful exploitation requires compromise or malicious control of an upstream package release or distribution path.

Attack Path

  1. A user has a legitimate or previously reviewed version of smartchart.
  2. An attacker gains the ability to publish a harmful release or manipulate the resolved artifact.
  3. The user follows the reference documentation and runs pip install --upgrade smartchart.
  4. Pip downloads and installs the attacker-controlled latest release.
  5. Package installation code may execute immediately.
  6. Subsequent invocations of smartchart run_tool execute the altered CLI, potentially exposing query inputs, outputs, credentials, or local resources.

Impact Assessment

The compromised package operates with the installing or invoking user's privileges. It could read or modify user-accessible files, collect environment-based credentials, inspect SmartChart parameters and query results, or communicate with network services reachable by that user.

The repos ...[truncated 226 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace installation and upgrade-to-latest commands with an exact reviewed version.
  2. Maintain dependency hashes in a version-controlled requirements or lock file.
  3. Require hash verification during installation.
  4. Remove the generic --upgrade recommendation; document a controlled update process involving source review, artifact verification, and testing.
  5. Configure an approved package index or internal artifact repository where practical.
  6. Install the CLI in an isolated virtual environment under a least-privileged account.
  7. Record the expected package origin, publisher, and version so package identity can be independently verified.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to invoke a shell-accessible CLI (smartchart) but does not declare any permissions or allowed-tools scope. This creates an authorization gap where a broadly triggered skill can cause command execution without explicit tool-use constraints, increasing the chance of unintended or unsafe shell actions in agent environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text covers generic requests like querying data, listing tools, fetching metrics, and data retrieval tasks, which are common across many contexts. An overly broad trigger can cause this shell-capable skill to activate when the user did not explicitly ask to use SmartChart, leading to unnecessary CLI execution and possible exposure to remote datasets or unintended operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documentation is entirely written in Chinese and presents the skill as a general SmartChart querying skill, but it does not state that Chinese is optional or that the skill is restricted to a Chinese-speaking context. For a general-purpose skill, this can amount to an implicit language policy constraint without user opt-in.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/smartchart_query.py (reported line 29)May include surrounding context.

python
if extra_args:
        cmd.extend(extra_args)
    print(f"[执行命令] {' '.join(cmd)}", file=sys.stderr)
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        print(f"[错误] {result.stderr}", file=sys.stderr)
        sys.exit(result.returncode)

Static analysis

No suspicious patterns detected.