Back to skill

Security audit

R ggplot Quickplot

Security checks for vulnerabilities and agentic risk

Overview

The skill is a CSV-to-ggplot chart helper, but it silently installs an unpinned R package at runtime and its advertised container workflow is incomplete and loosely scoped.

Review before installing. This skill should not be treated as a clean offline plotting helper: running the local script may install R packages from the network, and the container workflow appears incomplete unless you supply or verify the missing build/runtime files. Use it only in a controlled environment, prefer pinned dependencies or a reviewed container image, and avoid running it from a directory containing unrelated private files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
run.sh:11
Finding

Unpinned Third-Party Package Installation During Runtime

Content
View full analysis
/dev/null; then echo "Error: Rscript was not found" echo "Install R version 4.0 or later" echo "Download: https://cran.r-project.org/" exit 1 fi # Check whether ggplot2 is installed Rscript -e "if(!requireNamespace('ggplot2', quietly=TRUE)) install.packages('ggplot2')" 2>/dev/null ``` Related installation instructions also appear in: - `SKILL.md:85` - `SKILL.md:319-327` - `SKILL.md:335` - `skills/r-ggplot-quickplot/SKILL.md:194-210` ### Technical Analysis The runtime launcher automatically installs `ggplot2` if it is not already available. The installation does not specify an exact package version, trusted repository, integrity hash, signature, or lockfile. It therefore relies on the R repository configuration and dependency resolution state present on the executing system. R package installation can execute package installation hooks and native build operations with the privileges of the user running the Skill. If the configured repository, repository selection mechanism, package account, or upstream release is compromised, attacker-controlled installation code could run locally. The command also redirects standard error to `/dev/null`, concealing repository warnings, compilation errors, and other diagnostic information that could alert the user to an unexpected installation source or behavior. ### Attack Path 1. The target system does not already have `ggplot2` installed. 2. An attacker compromises or influences the R repository configured for that environment, or compromises a package or transitive dependency distributed through that repository. 3. The user invokes `run.sh`. 4. The launcher calls `install.packages('ggplot2' ...[truncated 665 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
build_docker.sh:7
Finding

Argument Injection Through Unquoted Image Names and Tags

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code is broadly consistent with a CSV-to-ggplot visualization tool because it accepts an input file and launches an R plotting script. However, the supplied chunk does not implement or demonstrate Docker/Singularity-based no-install execution as stated in the description; instead it requires a local R installation. Additionally, it has an undeclared capability of installing ggplot2 automatically from CRAN, which involves network/package-management behavior not mentioned in the declared permissions or purpose. Since the evaluation criteria say to flag undeclared capabilities and materially inconsistent resource/access behavior, this is a mismatch.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README consistently presents instructions and descriptions in Chinese, including the title and operational guidance, but does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking context. Per the policy, forcing a specific language without user opt-in is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese, and the rest of the skill documentation also consistently uses Chinese without indicating multilingual support or user opt-in. Under the stated policy, forcing a specific language without choice or clear regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The documentation instructs users to pull a container image using the mutable latest tag rather than a pinned version tag or immutable digest. This creates a supply-chain risk because the content behind latest can change over time or be replaced, causing users to run unreviewed or malicious code without noticing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments and all user-visible status messages are written in Chinese, which imposes a specific language on users without any opt-in or alternative locale support. Under the policy, language constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script claims a near zero-install local plotting workflow, but it conditionally fetches and installs ggplot2 from CRAN at runtime. This introduces network-based supply chain risk, breaks the expected trust boundary for a local CSV-to-chart tool, and can cause unreviewed code execution during a normal run.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

For a simple plotting wrapper, installing packages at execution time is broader capability than necessary and expands the attack surface beyond reading a CSV and generating charts. Even if intended for convenience, it allows remote code retrieval and execution in a context where users may not expect outbound network access or environment modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script silently installs an R package over the network without warning or confirmation, which can surprise users and execute code from an external source. In a local data visualization tool, this is especially risky because users reasonably expect offline processing of their CSV rather than implicit network activity and system changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and runtime output are written in Chinese, including usage/help and error messages later in the file. This imposes a specific language on users without opt-in or justification, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The script runs a local Docker image by name only and never pins it to a specific tag or immutable digest. This can lead to unintended or tampered image versions being executed if the local tag is rebuilt, replaced, or sourced differently than expected, which matters because the container processes user-supplied CSV data and writes files to a host-mounted output directory.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The launcher bind-mounts the entire current working directory into the container at /app/workdir, even though the stated task only requires one input CSV and an output directory. If the container image or invoked R script is compromised or behaves unexpectedly, it can read unrelated files from the host working tree, increasing the blast radius and potentially exposing source code, credentials, or other sensitive local data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill description is written in Chinese, including usage instructions and metadata, but there is no indication that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill documentation and user-facing description are written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill input-format document is written only in Chinese, including headings, requirements, examples, and FAQs, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically installs the ggplot2 package from the network at runtime, which exceeds the narrow stated purpose of visualizing a provided CSV file. This introduces an unnecessary supply-chain and network-execution risk because running the skill can fetch and execute remote package installation logic without explicit user consent or pinning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script performs a silent, unprompted package installation over the network, which means users may trigger remote dependency retrieval and package install side effects simply by running a plotting helper. In the context of a CSV-to-plot skill, this behavior is broader than expected and increases supply-chain exposure, especially because no confirmation, integrity control, or warning is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file explains that charts are automatically saved to the output/ directory, which is a file-writing behavior that affects the user's filesystem. The description does not include any warning or disclosure about possible overwrites, generated files, or storage impact.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · build_docker.sh (reported line 57)May include surrounding context.

sh
echo "镜像已构建完成"
    echo ""
    echo "本地测试运行:"
    echo "  docker run --rm -v \$(pwd)/output:/app/output $IMAGE_NAME:$TAG"
fi

echo ""

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments and all user-facing echo messages are written in Chinese, which imposes a specific language on users without any opt-in or stated regional justification. Under the policy, locale or language constraints should either be optional or clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest contains natural-language configuration commentary in Chinese, including the file description and version header, while the visible user-facing labels later mix in English. That creates a locale policy concern because the file imposes a specific language context without any opt-in or documentation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and it does not mention that the skill supports multiple languages or that Chinese is an optional locale. Under the policy rule for natural-language constraints, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's comments and runtime messages are presented only in Chinese, with no option for the user to choose another language or indication that the skill is intentionally limited to a Chinese-speaking context. This can violate a language/locale policy where user-facing behavior should not force a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file includes comments and operational messages in Chinese, and all user-facing status/error output is presented only in Chinese. This imposes a specific language on users without opt-in, which matches the locale-policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.