Back to skill

Security audit

Agent Lens

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent cost-tracking purpose, but its setup tells users to install mutable code directly from GitHub without a pinned version or integrity check.

Review or pin the GitHub package before installing, preferably to a specific audited commit or a trusted package-registry release. Install only in a virtual environment without elevated privileges, and assume the tool may see any prompts, responses, usage data, and environment available to the instrumented process.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:24
Finding

Unpinned Remote Package Installation Allows Payload Substitution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 24
Vulnerability Type: Unpinned installation of executable code from a remote repository
Risk Level: High

bash
pip install git+https://github.com/lrg913427-dot/agent-lens.git

Technical Analysis

The Quick Start instructions install a Python package directly from the default revision of a remote Git repository. The URL does not specify a reviewed commit hash, immutable release tag, package version, or integrity hash.

Consequently, the code executed by this command can change after the Skill has been audited. A Python package installation can invoke package build logic and installs modules that users are subsequently instructed to import and execute. Control of the repository, its default branch, or the associated GitHub account would therefore allow a substituted payload to execute during installation or later package use.

The audit did not establish that the current remote repository is malicious. The vulnerability is the mutable, unverified remote execution path and the resulting inability to bind installation to the reviewed content.

Attack Path

  1. An attacker compromises the repository owner account, gains write access to the repository, or otherwise causes malicious content to be served from its default branch.
  2. The attacker modifies package source code or installation/build configuration to contain a malicious payload.
  3. A user follows the documented Quick Start command.
  4. pip retrieves the repository's current content rather than a revision fixed at audit time.
  5. Malicious build hooks may execute during installation, or the installed payload executes when the documented agent_lens package or agent-lens command is used.
  6. The payload operates with the privileges and environmental access of the user running pip or invoking the installed package.

Impact Assessment

Successful exploitation could provide arbitrary co ...[truncated 715 chars]

Remediation
View remediation

Remediation Suggestions

  1. Publish the dependency through a controlled package registry and require an exact, reviewed version.
  2. Use hash-verified installation, such as a locked requirements file with --require-hashes, so altered artifacts are rejected.
  3. If installation from Git is unavoidable, pin the URL to a full reviewed commit SHA rather than a branch or mutable tag:
    bash
    pip install "agent-lens @ git+https://github.com/lrg913427-dot/agent-lens.git@FULL_REVIEWED_COMMIT_SHA"
    
  4. Record the expected commit identity and verify signed commits or release signatures where available.
  5. Review the pinned package source, including pyproject.toml, setup.py, build backend configuration, console entry points, and imported runtime modules.
  6. Perform installation in an isolated virtual environment without administrator privileges and with sensitive environment variables removed.
  7. Add automated dependency monitoring and require security review before updating the pinned revision.
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
95% confidence
Finding

The skill instructs users to install the package directly from a GitHub repository using pip install git+https://..., which bypasses the trust and integrity controls of a registry-pinned release and executes arbitrary package build/install code from the remote source. If the repository is compromised, renamed, force-pushed, or the referenced default branch changes, a user following the skill could run attacker-controlled code during installation.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

usage, and optimize costs.

When to Use

Activate this skill when the user:

  • Says "how much am I spending", "token usage", "API costs"
  • Wants to know which model is most expensive
  • Needs to optimize prompt costs
  • Wants to track API call latency or error rates
  • Mentions "budget", "cost optimization", or "token counting"
  • Asks "why is my API bill so high"

Quick Start

bash
# Install
pip install git+https://github.com/lrg913427-dot/agent-lens.git

# Generate demo data and see it in action
agent-lens demo

# View stats
agent-lens stats
agent-lens cost
agent-lens recent

Three Ways to Track

1. Decorator (easiest)

python
from agent_lens import AgentLens

lens = AgentLens(agent_name="my-agent")

@lens.track(model="gpt-4o")
def call_api(prompt):
    return client.chat.completions.create(
        model="gpt-4o",
        messages=[{"role": "user", "content": prompt}],
    )

# Token usage is auto-extracted from OpenAI-style responses
result = call_api("Hello")

Static analysis

No suspicious patterns detected.