Back to skill

Security audit

Code Inspector

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible local code scanner, but its reviewed package does not match several advertised checks and its install instructions pull mutable code from GitHub without pinning a reviewed version.

Install only if you are comfortable reviewing or pinning the GitHub source first. Treat the tool as a heuristic local scanner, not a complete security gate, because several checks advertised in SKILL.md are not present in the inspected implementation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Installation from a Mutable Git Repository

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 24
Vulnerability Type: Unpinned VCS dependency installation
Risk Level: Medium

Vulnerable Code

bash
pip install git+https://github.com/minirr890112-byte/code-inspector.git

Technical Analysis

The installation command retrieves the package from the repository's current default branch without pinning an immutable commit or verifying an artifact hash. Consequently, the code installed by a user may differ from the version covered by this audit.

Python package installation can execute build-backend logic and install executable package code. If the upstream repository, maintainer account, or default branch is compromised, an attacker could introduce malicious build or runtime code that is retrieved when a user follows these instructions.

The audited project currently declares ordinary dependencies (click and rich) and contains no confirmed malicious implementation. The risk arises from the mutable installation source rather than from a malicious payload observed in the reviewed files.

Attack Path

  1. An attacker compromises the upstream repository, its maintainer credentials, or a workflow able to modify the default branch.
  2. The attacker adds malicious package code or build-time behavior.
  3. A user follows the documented unpinned pip install git+https://... command.
  4. pip retrieves the attacker-controlled default-branch revision.
  5. Malicious build or package code executes during installation or when the installed CLI is invoked.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user running pip or invoking the installed package. This may permit access to that user's files, environment variables, credentials, network access, and other resources available to the process. It does not inherently grant elevated operating-system privileges unless installation is performed by a privileged account.

The network-li ...[truncated 348 chars]

Remediation
View remediation

Remediation Suggestions

  1. Publish reviewed releases through a trusted package registry and require an exact version.
  2. Use lock files and hash verification where supported, for example pip install --require-hashes -r requirements.txt.
  3. If installation directly from Git is necessary, pin the dependency to a reviewed full commit SHA:
bash
pip install "code-inspector @ git+https://github.com/minirr890112-byte/code-inspector.git@<full-reviewed-commit-sha>"
  1. Protect upstream releases and repository changes with multi-factor authentication, branch protection, mandatory review, and signed tags or commits.
  2. Build and publish reproducible artifacts through a protected release workflow, and verify their provenance before installation.
  3. Avoid running package installation as root or another privileged account; use an isolated virtual environment with only the permissions required by the scanner.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims security-oriented scanning coverage, including unsafe eval/exec and unused imports, but the analyzed behavior reportedly does not implement those checks and instead focuses on narrower heuristics. This mismatch can create a false sense of assurance, causing users to trust a 'production-ready' score while critical classes of defects go undetected.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

crets, catches exceptions with bare except/pass, and uses mutable defaults. You deploy it. It breaks. Reddit is full of "I let Claude loose and it broke the entire site" stories.

The solution: One command scans any Python file for 8 categories of AI-code bugs. Critical → High → Medium → Low severity. Production-readiness score 0-100. Don't deploy AI code blind.

Quick Start

bash
pip install git+https://github.com/minirr890112-byte/code-inspector.git

code-inspector app.py           # scan a file
cat app.py | code-inspector     # scan from pipe

What It Checks

CheckSeverityExample
Hardcoded secrets🔴 criticalapi_key = "sk-abc123"
Unsafe eval/exec🔴 criticaleval(user_input)
Infinite loops🔴 criticalappend-while-iterating
Mutable defaults🟠 highdef fn(items=[])
Shadowed builtins🟠 highlist = [1,2,3]
Bare except/pass🔴 criticalexcept: pass
D

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises behaviors implying file access, shell usage, and network use, but it does not declare any explicit tool scope or permission boundaries. In an agent ecosystem, missing scope declarations can lead to overbroad runtime capabilities, weak reviewability, and accidental authorization of risky operations beyond what users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documentation is presented in Chinese from the opening description onward, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, language-specific behavior or presentation without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: setuptools has 10 known advisory(ies) (CVE-2013-1633 (Setuptools vulnerable to Man-in-the-middle attacks); CVE-2025-47273 (setuptools has a path traversal vulnerability in PackageIndex.download that lead); CVE-2024-6345 (setuptools vulnerable to Command Injection via package URL) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: wheel has 4 known advisory(ies) (CVE-2026-24049 (Wheel Affected by Arbitrary File Permission Modification via Path Traversal in w); CVE-2022-40898 (pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)); CVE-2022-40898 (An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlie) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: click has 1 known advisory(ies) (CVE-2026-7246 (Pallets Click, versions 8.3.2 and below, contain a command injection vulnerabili)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pytest has 2 known advisory(ies) (CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.