Back to skill

Security audit

Agent Lens

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local cost-tracking helper, but its install instructions pull executable code from an unpinned external GitHub repository.

Review the external `agent-lens` repository before installing, prefer a pinned commit or verified release in an isolated virtual environment, and avoid tracing sensitive production prompts or metadata unless you understand what the local SQLite database stores and how to clean it up.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Third-Party Package Installation from a Mutable Git Repository

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–27
Vulnerability Type: Unpinned dependency retrieved from an unsafe mutable source
Risk Level: Medium

bash
# Install
pip install git+https://github.com/lrg913427-dot/agent-lens.git

Technical Analysis

The documented installation command retrieves and installs the current default branch of a third-party personal GitHub repository. It does not specify an immutable release tag or full commit SHA, and it provides no cryptographic hash, signature, or provenance verification.

Consequently, the code installed by users can differ from the code that was originally reviewed. Python package installation may execute repository-controlled build or installation logic. A malicious commit, compromised maintainer account, repository ownership transfer, or other supply-chain compromise could therefore introduce code that runs during installation.

The project contains only SKILL.md; the referenced external repository and its package implementation were not included in the audit scope. No claim is made that the current external package is malicious. The confirmed issue is the unsafe, mutable installation mechanism.

Attack Path

  1. An attacker compromises the repository maintainer account, gains control of the repository, or causes a malicious commit to enter its default branch.
  2. The attacker adds malicious Python packaging, build, or runtime code.
  3. A user follows the Skill documentation and runs the unpinned pip install git+https://github.com/lrg913427-dot/agent-lens.git command.
  4. pip downloads the repository’s current attacker-controlled content rather than an immutable reviewed revision.
  5. Malicious build or installation code executes with the privileges of the user running pip; malicious runtime code may also execute when the package is imported or its CLI is invoked.

Impact Assessment

Successful exploitation could provide arbit ...[truncated 627 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer a reviewed package published through a trusted registry and pin an exact version rather than installing the repository’s mutable default branch.
  2. Use a lock file or requirements file with cryptographic hashes, such as pip hash-checking mode, to verify downloaded artifacts.
  3. If Git installation is unavoidable, pin the dependency to a reviewed full commit SHA instead of a branch or floating tag.
  4. Verify signed commits or release artifacts and document the expected repository owner, revision, and artifact digest.
  5. Review the dependency’s source code and packaging configuration before approving an updated revision.
  6. Perform installation in an isolated virtual environment or sandbox using a non-privileged account, and avoid exposing unnecessary credentials during installation.
  7. Establish an update process in which dependency revisions are explicitly reviewed, tested, and approved before changing the pinned version.
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
88% confidence
Finding

The quick-start instructions tell users to install the tool directly from a GitHub repository using pip install git+https://..., which bypasses stronger supply-chain controls such as pinned releases, hashes, or curated package indexes. For a skill intended to be followed by users, this is dangerous because it encourages execution of remote code from a moving target repository, increasing the risk of compromise if the repo, owner account, or dependency chain is tampered with.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

usage, and optimize costs.

When to Use

Activate this skill when the user:

  • Says "how much am I spending", "token usage", "API costs"
  • Wants to know which model is most expensive
  • Needs to optimize prompt costs
  • Wants to track API call latency or error rates
  • Mentions "budget", "cost optimization", or "token counting"
  • Asks "why is my API bill so high"

Quick Start

bash
# Install
pip install git+https://github.com/lrg913427-dot/agent-lens.git

# Generate demo data and see it in action
agent-lens demo

# View stats
agent-lens stats
agent-lens cost
agent-lens recent

Three Ways to Track

1. Decorator (easiest)

python
from agent_lens import AgentLens

lens = AgentLens(agent_name="my-agent")

@lens.track(model="gpt-4o")
def call_api(prompt):
    return client.chat.completions.create(
        model="gpt-4o",
        messages=[{"role": "user", "content": prompt}],
    )

# Token usage is auto-extracted from OpenAI-style responses
result = call_api("Hello")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly states that API trace data is stored locally in a SQLite database, but it does not warn that traces may include sensitive prompts, model metadata, timing data, or other usage details that can persist on disk. In the context of an observability/cost-tracking skill, this creates a real privacy and data-retention risk because users may enable tracing on production agent traffic without realizing sensitive data may be recoverable later from the local database.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.