Back to skill

Security audit

Graph Analysis

Security checks for vulnerabilities and agentic risk

Overview

This graph-analysis skill is mostly coherent, but its setup command asks users to bypass Python environment protections and install unpinned packages into the system Python environment.

Install only in an isolated virtual environment or container, avoid `--break-system-packages`, and choose explicit output paths if `graph.png` or `communities.png` could overwrite existing files. The skill itself appears focused on graph analysis and does not show hidden exfiltration, persistence, or destructive behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Dependencies Installed into the System Python Environment

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22-26
Vulnerability Type: Unpinned and unsafe system-wide dependency installation
Risk Level: Medium

Vulnerable Code

markdown
Before first use, install dependencies:

```bash
pip install networkx matplotlib numpy --break-system-packages
text

### Technical Analysis

The setup command installs three dependencies without version constraints, package hashes, or a reviewed lockfile. Consequently, the code installed by this skill can change over time even when the skill itself remains unchanged.

The command also uses `--break-system-packages`, which deliberately bypasses Python environment protections intended to prevent `pip` from modifying an externally managed system Python installation. This can overwrite or conflict with packages used by unrelated applications.

Package installation may execute package build hooks and installation logic. If the configured package index, a transitive dependency, or a future package release is compromised, following this instruction could execute attacker-controlled code. The risk is increased when the command is run with elevated privileges or inside an environment containing sensitive credentials.

### Attack Path

1. A user or agent follows the setup instructions in `SKILL.md`.
2. `pip` resolves the latest available versions of `networkx`, `matplotlib`, `numpy`, and their applicable dependencies from the configured package index.
3. An attacker compromises a package release, dependency, package-index configuration, or dependency resolution path.
4. `pip` downloads the attacker-controlled distribution.
5. Malicious build or installation logic executes with the privileges of the account running `pip`.
6. Because `--break-system-packages` permits changes to the externally managed Python environment, the installation can also alter packages used by unrelated system applications.

### Impact Assessment

Successful exploitation can execute arbitrary
...[truncated 677 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create and use an isolated virtual environment rather than modifying the system Python installation:
bash
python3 -m venv .venv
. .venv/bin/activate
python -m pip install --upgrade pip
python -m pip install -r requirements.txt
  1. Remove --break-system-packages from all installation instructions.

  2. Pin reviewed dependency versions in a requirements or lock file, including relevant transitive dependencies.

  3. Generate and verify cryptographic hashes for distributions. For example, maintain a hash-locked requirements file and install it with:

bash
python -m pip install --require-hashes -r requirements.txt
  1. Configure an explicitly trusted package index and avoid unreviewed mirrors or additional indexes that could enable dependency confusion.

  2. Run dependency vulnerability and provenance checks as part of maintenance and CI, and update pinned versions through a controlled review process.

  3. Document that dependency installation must run as an unprivileged user and must not be invoked through sudo.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The setup command instructs users to run 'pip install ... --break-system-packages', which weakens Python environment protections and can modify system-managed packages. In shared, managed, or production environments, this can destabilize the host, create dependency conflicts, or encourage unsafe privilege escalation patterns for future package installs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The visualization section saves output to 'graph.png' and later to 'communities.png', which affects user files, but the skill description does not explicitly warn that running these examples creates or overwrites local PNG files. Under the markdown-file criteria, behaviors affecting user data or system state should be disclosed.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The 'When to Use This Skill' section lists broad triggers such as 'Analyze relationships, connections, or networks in data' and 'Visualize a network or relationship diagram' without any exclusion conditions or tighter scope boundaries. In a markdown skill description, this can make invocation criteria ambiguous because many ordinary data-analysis requests could match these phrases.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.