Back to skill

Security audit

Dxf Handle

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small CAD measurement helper whose local file reads and optional CSV write are disclosed and aligned with its stated purpose.

Install in a virtual environment, consider pinning `ezdxf` to a reviewed version, and choose `--output` paths carefully because CSV export writes to the specified local file.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–14
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code:

bash
pip install ezdxf

Technical Analysis

The installation instructions resolve the latest available version of ezdxf and its transitive dependencies at installation time. The project provides no exact version constraint, lockfile, integrity hashes, or explicitly trusted package index.

Consequently, the installed code can change after this Skill has been audited. This exposes users to supply-chain threats such as compromise of the legitimate package or one of its transitive dependencies. It can also introduce unreviewed behavioral or compatibility changes.

The audit found no evidence that the project intentionally uses dependency confusion, typosquatting, or an untrusted package source. The risk arises from mutable, unverified dependency resolution.

Attack Path

  1. An attacker compromises the published ezdxf package, a resolved transitive dependency, or the relevant package-distribution channel.
  2. A user follows the documented setup command:
    bash
    pip install ezdxf
    
  3. pip resolves and downloads the currently published, unpinned artifacts.
  4. Malicious package code executes during installation or when scripts/dxf_handle.py imports ezdxf.
  5. The malicious code operates with the privileges and filesystem access of the user running the installation or script.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing or invoking user's account. The resulting access may include reading or modifying files available to that account, including CAD documents and generated output, and making network requests if the environment permits them.

The reviewed project itself does not request elevated privileges, establish persistence, access credentials, or perform network communication. Therefore, the potential sco ...[truncated 75 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin ezdxf to an explicitly reviewed version rather than resolving the latest release:
    text
    ezdxf==<reviewed-version>
    
  2. Generate and commit a dependency lockfile containing cryptographic hashes for ezdxf and every transitive dependency.
  3. Require hash verification during installation, for example:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Explicitly use the approved official package index and prohibit unexpected additional indexes:
    bash
    python -m pip install --index-url https://pypi.org/simple --require-hashes -r requirements.txt
    
  5. Install dependencies in an isolated virtual environment using a non-privileged account.
  6. Periodically review and update pinned dependencies after vulnerability and provenance checks.
  7. Consider documenting package-signing or provenance-verification procedures where supported by the deployment environment.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation describes capabilities that read input files and optionally write CSV output, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent setting, missing scope declarations can cause the skill to run with broader ambient file access than intended, increasing the risk of unintended local file reads or writes if the skill is invoked on attacker-influenced paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Markdown advertises CSV export via --output but does not clearly warn users that this will create or overwrite a local file. While the behavior is expected for a CLI tool, the lack of disclosure can lead to accidental writes, especially in automated agent workflows where file system side effects should be explicit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The layer names and descriptions are entirely specified in Chinese, and the file provides no indication that this locale is optional or constrained to a justified region-specific use case. The policy explicitly calls for flagging language or locale constraints when they are imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest says the skill uses ezdxf to read drawings, traverse layer information, and calculate area or perimeter for room measurement statistics. In addition to those read/compute operations, the code accepts an output path and writes a CSV report to disk, which is extra behavior not reflected in the description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.