Back to skill

Security audit

pyscripts-org

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local Python-script organization helper, but its documentation and bundled summary script are inconsistent enough that users should treat it as rough tooling.

Install only if you want an agent to manage local Python utility-script documentation. Review the generated files before committing them, avoid storing secrets or sensitive error details in pitfall notes, and do not let the agent run existing scripts unless you understand what those scripts do.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill promises a broad workflow that includes consulting existing docs, running existing scripts, reading failing code, recording pitfalls, and maintaining specific documentation files, but the described implementation is much narrower and inconsistent. This mismatch is dangerous because users or agents may trust the skill to provide governance and safety checks that are not actually enforced, leading to unsupervised script execution or stale/inaccurate documentation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs the agent to read, modify, and generate repository files such as pyscripts_docs.md and pyscripts_pitfall.md, but it does not declare an explicit tool scope or permissions boundary. That creates an authorization ambiguity where an agent may perform file operations more broadly than a user expects, increasing the chance of unintended repository modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to automatically update pyscripts_docs.md and maintain pyscripts_pitfall.md without an explicit warning that repository files will be changed. In context, this is dangerous because documentation writes are triggered as part of routine script handling, which can create silent, unexpected modifications and accidental persistence of sensitive error details.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to match ordinary Python development activity, so the skill may activate in many situations beyond the author's intended scope. Over-broad activation is risky because it can cause the agent to read code, run scripts, or rewrite documentation opportunistically during normal work, expanding the skill's effective authority.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill automatically generates pyscripts_docs.md and enforces a summary block at the END of every .py file. This script instead looks for a # ----- delimiter anywhere in the file and writes output to py_docs.md, so the implemented behavior does not align with the declared skill contract.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains natural-language comments and console messages in Vietnamese only, including the script description and status output. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation because the skill does not offer any locale or language choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes a broader workflow: consult existing docs before writing new scripts, run existing scripts when found, and maintain pyscripts_pitfall.md for common errors. This file only scans local .py files and writes a documentation markdown file, leaving key claimed behaviors unimplemented in the actual code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.