Back to skill

Security audit

Content Writer Pro

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a straightforward local copywriting helper, with only low supply-chain hygiene concerns from unnecessary unpinned Python dependencies.

Before installing, consider removing unused dependencies or pinning them with a lockfile. The skill itself appears to run locally and generate text from templates, so the main practical risk is ordinary Python package-install exposure rather than hidden data access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
requirements.txt:5
Finding

Unnecessary and Unpinned Third-Party Dependencies Increase Supply-Chain Exposure

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:5-10; installation instruction at SKILL.md:30-34
Vulnerability Type: Unnecessary dependencies with unrestricted future versions
Risk Level: Low

Complete Code Snippet

requirements.txt:5-10:

text
# Core dependencies
jinja2>=3.0.0
pyyaml>=6.0

# Development dependencies
pytest>=7.0.0
pytest-cov>=4.0.0

SKILL.md:30-34:

markdown
## Installation / 安装

```bash
pip install -r requirements.txt
text

### Technical Analysis

The installation instructions cause four third-party packages to be installed with lower-bound-only version constraints. No exact versions, lock file, or package hashes are provided, so future installations may resolve to package releases that were not reviewed with this Skill.

None of these dependencies is imported by `content_writer.py`. Its implemented runtime functionality relies exclusively on Python standard-library modules. Consequently, `jinja2` and `pyyaml` are unnecessary for the declared runtime behavior, while `pytest` and `pytest-cov` are development tools that should not be part of the default runtime installation.

No evidence indicates that the currently named packages are malicious. The issue is the avoidable supply-chain attack surface and non-reproducible dependency resolution created by installing unused, unpinned components.

### Attack Path

1. A user follows the documented installation procedure and runs `pip install -r requirements.txt`.
2. `pip` queries the user's configured package index and selects any available versions satisfying the lower bounds.
3. If an allowed dependency release, transitive dependency, or configured package index is compromised, attacker-controlled package installation or import-time logic may be delivered.
4. The package logic executes under the privileges of the account or environment running `pip`.
5. The attacker may access data an
...[truncated 773 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove jinja2 and pyyaml unless corresponding runtime functionality is implemented and documented.
  2. Move pytest and pytest-cov into a separate development dependency file or optional development dependency group.
  3. Pin every retained dependency to a reviewed exact version.
  4. Use a lock file or hash-verified installation, such as pip install --require-hashes, to provide reproducible dependency resolution.
  5. Regularly scan retained direct and transitive dependencies for known vulnerabilities.
  6. Update SKILL.md so the default installation procedure installs only components required for runtime operation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The configuration example hard-codes language: 'zh-CN', which can be interpreted as a default language requirement or preferred output locale. The README does not indicate that language is user-selectable in this example context or explain why Chinese is required, which risks violating the language/locale choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file consistently frames the skill in Chinese and English, including the title, metadata, and overview, but does not state whether users can choose their preferred output language. This can create a language/locale policy concern if the skill defaults to a language or mixed-language behavior without explicit user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The initializer sets self.language to 'en' by default, which establishes an English locale preference in natural-language behavior without asking the user to choose. The file includes bilingual descriptions, so silently forcing English as the default can conflict with a language-choice policy unless the user explicitly opts in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code hard-codes bilingual English/Chinese text in the module docstring and throughout printed output, which imposes a specific locale choice rather than letting the user opt in. The policy specifically calls out language or locale constraints when a skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified as a lower-bounded range instead of a pinned version, which makes builds non-reproducible and can silently introduce vulnerable or incompatible releases over time. Because Jinja2 has a history of security advisories, leaving resolution open increases supply-chain risk and makes it impossible to verify whether deployed environments are patched.

Content

Scanner excerpt · requirements.txt (reported line 5)May include surrounding context.

text
# 文案生成专家 - 依赖

# Core dependencies
jinja2>=3.0.0
pyyaml>=6.0

# Development dependencies

Unverifiable Dependency: jinja2 has 16 known advisory(ies) (CVE-2019-10906 (Jinja2 sandbox escape via string formatting); CVE-2014-1402 (Incorrect Privilege Assignment in Jinja2); CVE-2025-27516 (Jinja2 vulnerable to sandbox breakout through attr filter selecting format metho) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Jinja2 has multiple known advisories, and because the manifest does not pin a version, there is no way to determine whether the installed package is affected. In a content-writing skill, templating libraries are plausibly used to render user-controlled content, so unresolved Jinja2 version risk is more concerning than it would be in an unrelated utility.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

PyYAML is unpinned, so the environment may resolve to different versions across installs, including versions with known unsafe parsing or input-validation flaws. Given PyYAML's history of deserialization-related vulnerabilities, this is a meaningful supply-chain and insecure-dependency risk even though the exact installed version is unknown from this file alone.

Content

Scanner excerpt · requirements.txt (reported line 6)May include surrounding context.

text
# Core dependencies
jinja2>=3.0.0
pyyaml>=6.0

# Development dependencies
pytest>=7.0.0

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
98% confidence
Finding

PyYAML has several historical vulnerabilities related to unsafe deserialization and input handling, and the lack of version pinning prevents verification that a safe release is installed. If this skill consumes YAML configuration or content data, an affected version could enable code execution or other serious compromise paths.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
87% confidence
Finding

The pytest dependency is not pinned, so test environments may drift and pull in versions with newly disclosed issues or breaking behavior. Since this is a development dependency, the direct production impact is lower, but it still affects build integrity and CI security.

Content

Scanner excerpt · requirements.txt (reported line 9)May include surrounding context.

text
pyyaml>=6.0

# Development dependencies
pytest>=7.0.0
pytest-cov>=4.0.0

Unverifiable Dependency: pytest has 2 known advisory(ies) (CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

pytest has known advisories, and without an exact version pin the development environment may resolve to a vulnerable release. This mainly affects CI or local test execution rather than runtime behavior, so the impact is comparatively limited.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
82% confidence
Finding

pytest-cov is also unpinned, creating non-reproducible development and CI environments that may unexpectedly ingest vulnerable or incompatible releases. While this is less severe than a runtime dependency, it still weakens supply-chain control.

Content

Scanner excerpt · requirements.txt (reported line 10)May include surrounding context.

text
# Development dependencies
pytest>=7.0.0
pytest-cov>=4.0.0

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code file includes a natural-language locale choice via the test configuration setting 'language': 'zh'. Under the policy, forcing a specific language without user opt-in can be a violation, and there is no indication here that the locale is optional or region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.