Back to skill

Security audit

data-scatter-plot

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow local CSV/Excel scatter-plot skill with ordinary file parsing and image output behavior.

Install only in an environment where reading the selected spreadsheet files and writing generated plot images is acceptable. For stronger supply-chain control, pin or lock pandas, matplotlib, openpyxl, and xlrd before production use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

描述前半部分(从CSV/Excel读取数据、解析Result/Min/Max Limit相关数据)与代码基本一致。但该代码块实际只是一个数据加载器和配置提取器,没有调用任何绘图库,也没有生成散点图或绘制Min/Max参考线,因此与“根据Result行数据生成散点图”这一核心声明存在明显落差。未发现额外危险能力或越权资源访问,主要问题是声明包含了代码中未实现的核心功能。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the entire user-facing documentation are written in Chinese, with no indication that other languages are supported or that the language restriction is intentional for a region-specific use case. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language strings that force a specific language/locale for documentation and user-facing text. Under the policy, language constraints should not be imposed without offering a user choice or documenting a justified region-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code forces a specific language for the module docstring, argument help text, examples, and runtime status messages. The file does not provide any user opt-in or locale selection, which matches the policy category for language or locale constraints without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module hard-codes Chinese font preferences via matplotlib rcParams, which imposes a specific language/locale presentation choice globally. This is a natural-language locale policy concern because users are not offered an opt-in or alternative locale behavior, and no region-specific justification is documented in the file.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency specification uses a lower-bound version range instead of pinning an exact version, which makes builds non-reproducible and can cause different environments to install different releases. This increases supply-chain risk because a vulnerable or incompatible future release could be pulled in without review.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pandas>=1.5.0
matplotlib>=3.5.0
openpyxl>=3.0.0
xlrd>=2.0.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

pandas has a known historical advisory, but because the manifest does not pin a version, it is impossible to determine whether deployed environments will receive a fixed or affected release. This uncertainty is a real security weakness because dependency resolution may select a vulnerable version in some environments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The matplotlib dependency is unpinned, so installations may resolve to different versions over time. While not directly exploitable by itself, this weakens build integrity and can introduce vulnerable or unexpected package versions into the environment.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
pandas>=1.5.0
matplotlib>=3.5.0
openpyxl>=3.0.0
xlrd>=2.0.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

openpyxl is unpinned, which creates uncertainty about which release will actually be installed and whether known security fixes are present. In a skill that reads Excel files, this matters more because parser libraries process attacker-controlled document content and historically have had XML-related issues.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
pandas>=1.5.0
matplotlib>=3.5.0
openpyxl>=3.0.0
xlrd>=2.0.0

Unverifiable Dependency: openpyxl has 2 known advisory(ies) (CVE-2017-5992 (Improper Restriction of XML External Entity Reference in Openpyxl); CVE-2017-5992 (Openpyxl 2.4.1 resolves external entities by default, which allows remote attack)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

openpyxl has known XXE-related advisories, and the dependency is not pinned, so there is no assurance that installations will use a patched version. This is more dangerous in this skill because it explicitly reads Excel files, meaning attacker-supplied spreadsheet content could reach a vulnerable parser if an affected version is installed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The xlrd dependency is specified with only a minimum version, allowing dependency resolution to pull in different future releases. This is a supply-chain hygiene issue that can lead to unreviewed code, regressions, or exposure to newly introduced vulnerabilities.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
pandas>=1.5.0
matplotlib>=3.5.0
openpyxl>=3.0.0
xlrd>=2.0.0

Static analysis

No suspicious patterns detected.