Back to skill

Security audit

wordcloud-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to generate word-cloud images as advertised, but its dependency-install instructions are unsafe enough to require review before installation.

Install dependencies manually in a virtual environment using reviewed package names such as jieba, numpy, wordcloud, and Pillow. Do not blindly install os, argparse, datetime, or PIL from a package registry. When using the skill, provide narrow file or directory paths and choose an output directory intentionally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unsafe and Incorrectly Named Third-Party Dependency Installation Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–21
Vulnerability Type: Supply-chain exposure through unpinned and incorrectly named dependencies
Risk Level: Medium

Vulnerable Code Snippet

markdown
Run on python3.x,and install the following packages if you find the package does not exist:
- os
- argparse
- jieba
- numpy
- datetime
- wordcloud
- PIL

Technical Analysis

The installation guidance does not pin package versions, verify package hashes, or specify an approved package index. It also incorrectly presents the Python standard-library modules os, argparse, and datetime as packages that may need installation.

In addition, the script imports Image through from PIL import Image, but the maintained distribution that supplies this namespace is Pillow, not a package that should be installed by blindly using the name PIL. An agent following the instructions literally could attempt to install standard-library lookalikes or an unintended distribution. This creates dependency-confusion, typosquatting, and compromised-release exposure.

Attack Path

  1. The skill is run in an environment where one of the documented imports is unavailable or appears unavailable.
  2. An agent or user follows the instruction to install the package whose import failed.
  3. The installer resolves an incorrect name such as PIL or a standard-library module name from an uncontrolled package registry.
  4. A malicious, impersonating, or compromised distribution is downloaded.
  5. Package installation hooks or imported package code execute with the privileges of the user or service performing the installation.

Exploitation depends on the operator or agent acting on the unsafe installation guidance and on a malicious package being resolvable from the configured registry.

Impact Assessment

A malicious dependency can execute arbitrary code with the privileges of the process performin ...[truncated 403 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove os, argparse, and datetime from the installation list because they are included in the Python standard library.
  2. Replace PIL with the correct maintained distribution name, Pillow.
  3. Declare only the required third-party distributions: jieba, numpy, wordcloud, and Pillow.
  4. Pin reviewed versions in a dependency manifest such as requirements.txt.
  5. Generate and enforce cryptographic hashes, for example by installing with pip --require-hashes.
  6. Restrict dependency resolution to an approved package index or internally controlled mirror.
  7. Add automated dependency vulnerability and provenance checks to the release process.
  8. Document installation through a virtual environment without administrative privileges.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents file-oriented capabilities such as reading a target file or recursively processing a target directory, but it does not declare any tool scope or permissions boundary. That makes the skill's effective access ambiguous and increases the risk of unauthorized or overly broad file reads if an agent invokes it without clear consent and policy checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description omits an explicit warning that the skill writes image files and may instruct the agent to modify stopwords.md. Hidden write behavior is dangerous because it can alter the workspace or persist user data without clear notice, especially when combined with file and directory inputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger guidance is broad enough that an agent may invoke this skill whenever a user wants to 'visualize text in a different way,' even if the user did not ask for file scanning or image generation. Overbroad invocation criteria can lead to unnecessary file access, unintended output creation, and surprising behavior that bypasses informed user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Using jieba as the sole tokenizer implies the skill is tailored to Chinese text processing, but the CLI and code do not clearly disclose this locale limitation or provide an opt-in choice for other languages. This can violate language/locale policy expectations when the skill is presented as generally applicable word-cloud generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The parameter description says to use a font 'useful for chinese text,' which steers the skill toward a specific language/locale without offering a user choice or documenting that this is a region-specific tool. This can conflict with language/locale policy expectations when handling multilingual input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code creates an output directory and saves a generated PNG file, which modifies the user's filesystem. Although this is part of the script's functionality, there is no visible confirmation prompt or user-facing disclosure in the code around these write operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.