Back to skill

Security audit

data-bird

Security checks for vulnerabilities and agentic risk

Overview

Data Bird appears to be a genuine data-analysis skill, but it needs Review because it can fetch internal URLs, use MySQL when enabled, and write reports outside the expected workspace.

Review before installing. Use only trusted files and URLs, block localhost/private-network downloads unless explicitly intended, avoid production MySQL credentials or unrestricted SQL, force outputs into a controlled workspace directory, and treat generated HTML reports from untrusted datasets as potentially unsafe to open or share.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:31
Finding

Unrestricted Internal-Network URL Retrieval Enables SSRF

Content
View full analysis
/data exec: curl -fsSL "" -o /data/table.csv ``` The surrounding instruction explicitly permits any downloadable URL, including localhost and internal-network URLs, and requires using `curl` rather than a restricted fetch facility. ### Technical Analysis The Skill directs the Agent to pass a user-controlled URL to `curl` without validating the destination. No controls restrict: - URL schemes - Loopback, private, or link-local addresses - Cloud metadata endpoints - DNS rebinding - Redirect destinations - Internal hostnames or ports - Response content type Although downloading a user-provided CSV or Excel file is part of the declared functionality, access to localhost and internal-network resources exceeds the minimum privileges needed. A public data-analysis Skill should not be able to retrieve arbitrary intranet or metadata resources. The `-L` option follows redirects, so validating only the initial URL would also be insufficient. ### Attack Path 1. An attacker asks the Agent to analyze a URL that resolves to an internal service, such as a loopback address, private-network host, or cloud metadata endpoint. 2. Following the Skill instructions, the Agent executes `curl -fsSL` with that URL. 3. The internal response is saved as a local file. 4. If the response can be parsed as tabular data, the analysis pipeline profiles and summarizes its content. 5. Generated JSON and reports may reveal internal data to the attacker. A public URL that redirects to an internal address could provide an equivalent path because redirects are followed. ### Impact Assessment Successful exploitation can provide read access to HTTP resources reachable from the Agent host but not from the attacker. Dependin ...[truncated 385 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/report_artifacts.py:287
Finding

Stored JavaScript Injection in Generated ECharts Reports

Content
View full analysis
None: out_path.parent.mkdir(parents=True, exist_ok=True) title = chart.get("title") or "Chart" option = json.dumps(chart.get("option") or {}, ensure_ascii=False) out_path.write_text( _html_page( title, f"""

{html.escape(title)}

""", ), encoding="utf-8", ) ``` The same unsafe pattern is used in the consolidated report: ```python ``` Upstream spreadsheet values reach these options through the following transformation: ```python return [str(x) for x in agg.index.tolist()], [float(v) for v in agg.tolist()], metric ``` ```python "xAxis": {"type": "category", "data": x_data, "name": x_label or ""}, ``` ### Technical ...[truncated 1830 chars]
Remediation
View remediation
... ``` Then read its `textContent` and parse it with `JSON.parse`. 3. Apply HTML-safe JSON encoding by replacing at least: - `<` with `\u003c` - `>` with `\u003e` - `&` with `\u0026` - U+2028 and U+2029 with escaped forms 4. Validate and constrain chart labels, titles, and option structures before rendering. 5. Add a restrictive Content Security Policy that disallows inline scripts and limits script sources. 6. Prefer a locally bundled and integrity-verified ECharts dependency. 7. Add regression tests using spreadsheet cells containing closing script tags and other HTML payloads. ]]>

T01 · Skill Instruction Hijacking

Warning
Location
scripts/insight_agent.py:184
Finding

Indirect Prompt Injection through Untrusted Dataset Content

Content
View full analysis
0: try: sample_block = df.head(3).to_string()[:600] except Exception: sample_block = "" data_summary = "\n".join( [ f"Rows: {row_count}", f"Scenario: {schema.get('scenario_label') or schema.get('scenario')}", f"Column names: {column_names}", f"Time column: {schema.get('detected_time_column')}", "## Field quality", _profile_brief(schema), "## Chart and conclusion hints", _analysis_brief(analysis), "## Numeric descriptive statistics", stats_block or "None", ] ) if sample_block: data_summary += f"\n## Raw row samples\n{sample_block}" ``` The untrusted content is then inserted into a model prompt and submitted without a separate system policy: ```python user_prompt = prompt_template.format( data_summary=data_summary, query=query or "General business analysis", ) if llm_call: try: content = llm_call("", user_prompt) ``` ### Technical Analysis Dataset column names, profile information, chart takeaways, user queries, and optionally raw row values are concatenated into an instruction-bearing prompt. The call passes an empty system message and does not establish a strong trust boundary telling the model that text inside the dataset must never be interpreted as instructions. A malicious spreadsheet can therefore place prompt-like instructions in column names or categorical values. These values may propagate into cha ...[truncated 1639 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/report_artifacts.py:36
Finding

Caller-Controlled Output Directory Allows Filesystem Writes outside the Workspace

Content
View full analysis
Path: options = context.get("options") or {} cfg = _load_config(skill_root) out_dir = options.get("output_dir") or cfg.get("output_reports_dir") or "" if out_dir: out_path = Path(out_dir) if not out_path.is_absolute(): out_path = _workspace_root() / out_path return out_path.resolve() return (_workspace_root() / "databird" / "output").resolve() ``` The resolved path is used without an allowed-root check: ```python def generate_report_artifacts(skill_root: Path, context: Dict[str, Any]) -> Dict[str, Any]: report_dir = _report_root_dir(skill_root, context) / _report_run_name(context) charts_dir = report_dir / "charts" images_dir = report_dir / "images" report_dir.mkdir(parents=True, exist_ok=True) charts_dir.mkdir(parents=True, exist_ok=True) images_dir.mkdir(parents=True, exist_ok=True) report_md_path = report_dir / "report.md" report_html_path = report_dir / "report.html" report_pdf_path = report_dir / "report.pdf" report_md_path.write_text(report_md, encoding="utf-8") ``` ### Technical Analysis The public `options.output_dir` input accepts absolute paths. Relative paths are joined to the workspace, but absolute paths are resolved and accepted without verifying that they remain under an approved report directory. The Skill subsequently creates directories and writes fixed report, chart, and image filenames. A caller who can provide `options` can therefore direct output to any location writable by the Agent process. The run name is slugified, which limits traversal through `job_id`, but it does not address an arbitrary absolute output root. Existing fil ...[truncated 1260 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unhashed Python Dependencies Create Supply-Chain Exposure

Content
View full analysis
=1.5.0 openpyxl>=3.0.0 mysql-connector-python>=8.0.0 PyYAML>=6.0 matplotlib>=3.8.0 reportlab>=4.0.0 xhtml2pdf>=0.2.13 ``` The documented installation command installs these open-ended requirements: ```bash pip install -r requirements.txt ``` ### Technical Analysis Every dependency uses an open-ended minimum version and no package hashes are supplied. Installation results therefore depend on the package versions and transitive dependencies available at installation time. This is not evidence that any listed package is malicious. However, it means the reviewed source does not define the exact code that will execute in a future installation. A compromised, malicious, or unexpectedly incompatible future release satisfying the minimum constraint could be selected automatically. Python package installation can execute build backends and package code with the privileges of the installing user, making dependency integrity part of the Skill's effective security boundary. ### Attack Path 1. An operator follows the documented installation command. 2. The package resolver selects the newest available releases satisfying the minimum-version constraints. 3. The resolver also selects uncontrolled transitive dependencies. 4. Package build or installation logic executes under the operator's account. 5. If a selected release or dependency is compromised, its code runs before the Skill itself is invoked. ### Impact Assessment A compromised dependency could obtain the privileges of the user performing installation and potentially: - Read or modify local files - Access environment variables and credentials - Install persistent components - Alter the analysis pipeline - Exfiltrate analyzed data during later execution No specific malicious package or known ...[truncated 153 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior does not align with the broader capabilities implied by the skill instructions and analysis findings, including undeclared database/network access patterns and incomplete or inconsistent implementation claims. Description-behavior mismatch is dangerous because it hides real attack surface from reviewers, leading users to trust a 'lightweight analysis' skill that may perform materially different operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs shelling out to curl for any downloadable URL, including localhost and internal network targets. This creates a classic SSRF and local network probing path, allowing a user prompt to cause requests to internal services or cloud metadata endpoints that are unrelated to normal CSV/Excel analysis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code enables direct MySQL connectivity and arbitrary SQL execution despite the published description only advertising local/HTTP(S) CSV/Excel analysis. This capability mismatch is security-relevant because it expands the trust boundary to internal databases, allows access to credentialed data sources, and could surprise users or reviewers who rely on the manifest to understand exposure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares operational behaviors that require file reads, file writes, environment/path awareness, and shell execution, but it does not declare any explicit tool scope or permissions. This weakens containment and reviewability because operators and users cannot clearly see what capabilities the skill expects before it handles local files and writes outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill description is presented in Chinese and describes outputs such as Chinese PDF/chart text support, but it does not indicate that users may choose another language. This can violate language/locale policy when a skill implicitly constrains interaction language without opt-in or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill normalizes downloading arbitrary URLs, including internal/local addresses, without presenting any privacy or security warning to the user. In context, this makes the data-analysis workflow more dangerous because users may not realize they are authorizing network access that can touch sensitive internal resources or pull untrusted files into the workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The comments and setting state that PDF generation will preferentially register and forcibly use a Chinese font. This is a natural-language locale/language constraint, and the file does not indicate that users can choose their language or opt in to this behavior; only a technical override mechanism is mentioned.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt explicitly requires responses in Chinese with no indication that the user can choose another language. This is a natural-language locale policy constraint and can violate organizational language-choice requirements when no opt-in is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains only Chinese-language instructions, which can force a specific language/locale on users without opt-in. The policy for natural-language content requires either offering a language choice or clearly documenting that the skill is intended for a specific locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction '请用中文' mandates a specific language regardless of user preference. Under the policy, forcing a language or locale without opt-in is a natural-language policy violation unless the constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill is described as a lightweight CSV/Excel analysis agent, but its dependency list includes mysql-connector-python, which enables direct database connectivity beyond the stated purpose. This expands the attack surface and capability set of the skill, increasing the risk of unintended data access, credential handling, or future code paths that query external databases without clear user expectation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring describes the agent entirely in Chinese and frames it as producing chart results for general business tables, with no indication that language output is optional or user-selectable. Under the stated policy, a locale-specific constraint should be opt-in or clearly justified; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module-level description states the agent generates chart options in Chinese, and the file consistently uses Chinese-language labels and descriptions. This is a natural-language locale policy issue because it imposes a specific language on the skill behavior without documenting user choice or opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The top-level docstring says the agent reads CSV/Excel/MySQL, but the manifest only advertises workspace tables and HTTP(S)-downloaded CSV/Excel. This indicates the shipped code/documentation exposes a broader purpose than the declared public scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module description is written to prescribe behavior in Chinese, including output expectations, without indicating that the user can choose another language. This is a natural-language locale policy issue because the skill appears to impose a specific language rather than offering choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill opens a live MySQL connection and executes SQL without any visible user-facing disclosure in this component, which can cause users to submit sensitive connection details or query internal data without understanding the risk. In an agent setting, undisclosed external data access is dangerous because it increases the chance of over-privileged use and accidental access to protected systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The code reads and uses database credentials, including a password, to establish a connection. For code files, access to sensitive credentials should have some visible disclosure, but there is no comment, docstring warning, or user-facing notice explaining this behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code allows an environment variable to silently enable inclusion of raw row samples in prompts sent to the LLM, overriding the safer default behavior stated in the module docstring. In a data-analysis skill that may process arbitrary workspace tables, this creates a hidden data-sharing path that can expose sensitive records without clear runtime disclosure or per-request consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

When enabled, the code serializes the first three raw dataframe rows and appends them to the LLM prompt, with no visible warning, consent flow, or redaction logic in this file. Because uploaded CSV/Excel data may contain personal, financial, operational, or credential-like values, even a few rows can leak highly sensitive information to an external model provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 中文输出 mandates a specific language for the generated report, and the file does not provide any user opt-in, locale selection, or documented region-specific reason for this constraint. This matches the policy category for language or locale restrictions imposed without choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated HTML hard-codes lang="zh-CN", which imposes a specific language/locale in output regardless of user preference. The file also contains extensive fixed Chinese UI text, but does not offer any opt-in, configuration, or explanation that this skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest advertises a broad natural-language data-analysis capability without stating clear activation boundaries, input trust assumptions, or limits on what data sources and operations are in scope. In an agent setting, vague triggers increase the chance of unintended invocation on sensitive datasets or user prompts that cause risky downstream behavior such as external fetching, report generation, or broad data processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest allows a datasource object with MySQL connectivity and mentions HTTP(S)-downloaded CSV/Excel in the skill description, yet it does not warn about external system access, credential handling, or sensitive data exposure. In context, this materially increases risk because the skill is a data-analysis agent that may process production databases or remote files, so users may inadvertently grant broad access without understanding network, privacy, and trust implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The outputs declare disk-written artifacts such as Markdown, HTML, PDF, and chart image paths, but the manifest does not warn users that running the skill may create persistent local files. This can lead to unanticipated data persistence, leakage of sensitive analysis results to shared storage, and unsafe assumptions by callers who expected in-memory-only processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file states that remote files are downloaded to local storage and that reports are written under workspace directories. While the paths are documented, there is no explicit user warning that the skill will create local files and persistent output artifacts affecting user data and storage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.