Back to skill

Security audit

FreeCAD

Security checks for vulnerabilities and agentic risk

Overview

This FreeCAD skill appears purpose-aligned, but users should know it writes and may overwrite local CAD output files.

Install only if you are comfortable with a local Python/FreeCAD engine creating or modifying CAD files in the working directory. Run it in a project folder where overwriting model.FCStd, model.step, or requested export filenames will not damage important work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description focuses on creating or modifying CAD models via parametric JSON, but the skill also states that it emits model.FCStd and model.step files and performs file output behavior not clearly disclosed in the purpose statement. This mismatch can mislead users and security policy engines about the real side effects, increasing the chance of unintended overwrites or unsafe approval of a more powerful skill than advertised.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill invokes a Python engine and, by its own description, produces output files and reads engine results, but it does not declare any explicit tool scope or permissions boundaries. That omission increases the risk of overbroad file/environment access at runtime and makes it harder for a host to enforce least privilege or for users to understand what capabilities the skill requires.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code loads or creates a CAD document and then saves/exports artifacts to fixed filenames, which can overwrite or create local files. Although this is part of the processing flow, the file itself provides no prompt, disclosure, or user-facing log indicating that local files will be written.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs direct, potentially irreversible modifications to a FreeCAD object's position, rotation, and geometry by updating placement fields and overwriting obj.Shape. There is no confirmation prompt, logging, print statement, or explanatory docstring/comment warning the user that the target object will be mutated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises output files but does not warn users that running it may write or overwrite files. Even if the intended outputs are benign CAD artifacts, silent file creation or replacement is a real safety issue because users may not expect persistent side effects or collisions with existing files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The function creates and populates a new Part::Feature in the document, which is a persistent document modification. In this file there is no confirmation prompt, user-facing log/print, or comment/docstring warning that running the skill will alter the current document.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs a file write by exporting model data to a local filename, but there is no confirmation prompt, explicit user-facing notice, or explanatory comment/docstring describing that an export file will be created. For code files, file writes should have some visible disclosure unless clearly documented elsewhere, which is not evident in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This function creates and inserts a new Part::Feature object into the provided or active document and assigns geometry to it, which is a file/document-modifying operation. The code contains no confirmation prompt, logging/print statement, or explanatory docstring/comment disclosing that it will alter the current document state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This code adds a new object to the active document and assigns geometry to it, which is a file/document-modifying operation. There is no confirmation prompt, logging/print statement, or explanatory comment/docstring in this file to disclose that running the skill will change the current FreeCAD document.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This function saves the active FreeCAD document and exports geometry to a STEP file, which are file-writing operations that can affect user data on disk. Although the docstring states what the function does, there is no user-facing confirmation, logging, or warning around these writes, and the code itself performs them silently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.