Back to skill

Security audit

perfetto-analyse

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Android Perfetto trace collection and analysis helper, with some dependency-integrity cautions but no hidden or malicious behavior found.

Install and run this only in an environment where Android trace data can be handled safely. Prefer pinned, reviewed versions of the perfetto package, verify any downloaded trace_processor binary when possible, and avoid running the install or analysis commands as root or with unnecessary privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:2
Finding

Unpinned and Unverified Perfetto Dependencies

Content
View full analysis

Vulnerability Details

File Location: scripts/requirements.txt:2, SKILL.md:139-140,151, and reference.md:53,63-64
Vulnerability Type: Supply-chain risk caused by mutable dependencies and an unverified executable download
Risk Level: Medium

Vulnerable Code

scripts/requirements.txt:2:

text
perfetto>=0.0.0

SKILL.md:139-140:

bash
curl -LO https://get.perfetto.dev/trace_processor
chmod +x ./trace_processor

SKILL.md:151:

bash
# 依赖: pip install perfetto(或 pip install -r perfetto-analyse/scripts/requirements.txt)

reference.md:53:

bash
pip install -r perfetto-analyse/scripts/requirements.txt   # 或 pip install perfetto

reference.md:63-64:

bash
curl -LO https://get.perfetto.dev/trace_processor && chmod +x ./trace_processor
./trace_processor trace.pftrace

Technical Analysis

The requirement perfetto>=0.0.0 has no upper bound, exact version, or integrity hash. Consequently, the dependency resolved during installation may differ from the version assessed during this audit. A compromised, malicious, or unexpectedly incompatible future release would be accepted automatically.

The documented alternative downloads trace_processor from a mutable URL, makes it executable, and instructs the user to run it without verifying a release version, cryptographic signature, or checksum. HTTPS protects data in transit but does not establish that the retrieved artifact is the exact artifact previously reviewed.

The referenced package and download domain are consistent with the Skill's declared Perfetto functionality. No evidence indicates that the current project intentionally distributes a malicious payload. The vulnerability is the absence of controls ensuring that future installed artifacts remain identical to audited artifacts.

Attack Path

  1. An attacker compromises the upstream package publication process, download ...[truncated 1246 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the open-ended requirement with an exact, reviewed version:

    text
    perfetto==<reviewed-version>
    
  2. Generate a lock file containing cryptographic hashes and install it with hash enforcement:

    bash
    python -m pip install --require-hashes -r requirements.lock
    
  3. Pin trace_processor to a specific official release rather than a mutable latest-download URL.

  4. Publish the expected SHA-256 digest in the project and verify it before granting execute permission:

    bash
    echo "<expected-sha256>  trace_processor" | sha256sum --check -
    chmod +x trace_processor
    
  5. Prefer signature verification when the upstream project provides signed releases. Document the trusted signing key and fail closed if verification is unsuccessful.

  6. Review and update pinned artifacts through a controlled dependency-update process that includes provenance validation, security scanning, and regression testing.

  7. Advise users not to install or execute analysis dependencies as root or through an unnecessarily privileged account.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill body is written entirely in Chinese starting at the title and continuing through the operational instructions, while the manifest description is in English. There is no statement that the skill is region-specific or that users may choose another language, which creates a language/locale policy concern under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains user-facing natural-language text that forces a specific language for usage instructions and help text. Under the policy, language constraints should either offer user choice or be clearly justified as locale-specific; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The parser description is user-facing output and is fixed to Chinese. Because the file does not offer an alternative language or explain a justified regional requirement, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script prints runtime messages exclusively in Chinese, which constrains user interaction to a single language. The policy allows this only when users can opt in or when the locale limitation is clearly documented and justified, which is not evident here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The only natural-language description in the file is written in Chinese, which can impose a language/locale constraint on users without offering a choice or documenting why that locale is required. The file content itself is otherwise locale-neutral, so this appears to be an undocumented language restriction rather than a justified regional requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The only natural-language description in the file is the comment on L01, which is written exclusively in Chinese. This can violate a language/locale policy when a skill or config presents user-facing guidance in a fixed language without offering a choice or documenting that the file is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language content in the file is written only in Chinese, including the title and usage comment, with no indication that the skill is intentionally region-specific or that another language option is available. Under the policy for natural-language content, this is a locale/language constraint that is not opt-in or justified in the file.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/query_trace.py (reported line 95)May include surrounding context.

python
elif isinstance(row0, dict):
        columns = list(row0.keys())
    else:
        columns = [k for k in dir(row0) if not k.startswith("_") and not callable(getattr(row0, k, None))]

    sep = "," if args.csv else "\t"
    if args.csv:

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/query_trace.py (reported line 106)May include surrounding context.

python
elif isinstance(row, dict):
            d = row
        else:
            d = {c: getattr(row, c, "") for c in columns}
        values = [str(d.get(c, "")) for c in columns]
        print(sep.join(values))

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency specifier perfetto>=0.0.0 is effectively unbounded and allows installation of any available version, including future releases with breaking changes or a compromised package version. In a security-sensitive automation or analysis workflow, this weakens supply-chain control and harms reproducibility, making builds and executions depend on whatever version is current at install time.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
# 供 query_trace.py 使用
perfetto>=0.0.0

Static analysis

No suspicious patterns detected.