Back to skill

Security audit

Agent Lens

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent cost-tracking purpose, but it asks users to install mutable third-party code from GitHub and persists trace data locally with limited data-handling detail.

Review or pin the GitHub package before installing, preferably to a trusted release or commit, and run it in an isolated environment. Treat the local trace database and any exports as potentially sensitive because they may reveal model usage, costs, timestamps, and possibly prompt-related context.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Installation from a Mutable Third-Party Git Repository

Content
View full analysis
Remediation
View remediation
``` 2. Prefer publishing and installing a fixed version from a trusted package registry: ```bash pip install agent-lens== ``` 3. Use package hashes and a locked dependency file where supported, and require hash verification during installation. 4. Review the package source, build configuration, installation hooks, transitive dependencies, network behavior, and handling of trace data before recommending it. 5. Run the package with least privilege in an isolated virtual environment or container. Do not install it as root or with access to unrelated secrets. 6. Establish a controlled update process in which new upstream revisions are reviewed and tested before the pinned reference is changed. ]]>
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
95% confidence
Finding

The skill instructs users to install directly from a GitHub repository using pip install git+https://..., which executes unpinned remote code from the repository at install time. This creates a supply-chain risk: if the repository, owner account, dependency chain, or default branch is compromised, users may run attacker-controlled code simply by following the documented setup.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

usage, and optimize costs.

When to Use

Activate this skill when the user:

  • Says "how much am I spending", "token usage", "API costs"
  • Wants to know which model is most expensive
  • Needs to optimize prompt costs
  • Wants to track API call latency or error rates
  • Mentions "budget", "cost optimization", or "token counting"
  • Asks "why is my API bill so high"

Quick Start

bash
# Install
pip install git+https://github.com/lrg913427-dot/agent-lens.git

# Generate demo data and see it in action
agent-lens demo

# View stats
agent-lens stats
agent-lens cost
agent-lens recent

Three Ways to Track

1. Decorator (easiest)

python
from agent_lens import AgentLens

lens = AgentLens(agent_name="my-agent")

@lens.track(model="gpt-4o")
def call_api(prompt):
    return client.chat.completions.create(
        model="gpt-4o",
        messages=[{"role": "user", "content": prompt}],
    )

# Token usage is auto-extracted from OpenAI-style responses
result = call_api("Hello")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly states that trace data is stored in a local SQLite database, but it does not prominently warn that API traces may include sensitive prompt content, model metadata, timestamps, and usage details written persistently to disk. In an observability skill, silent persistence increases privacy and data-handling risk because users may enable tracing in environments that process secrets, proprietary prompts, or regulated data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.