Back to skill

Security audit

Chart Animation

Security checks for vulnerabilities and agentic risk

Overview

The chart animation code is purpose-aligned, but the package metadata creates a real install-time supply-chain concern by declaring Python libraries as unpinned npm dependencies.

Review the install path before using this skill. Prefer installing Python dependencies in a virtual environment with pinned versions, ignore or remove the npm dependency block unless those packages are intentionally used, and install ffmpeg only from a trusted system package source if MP4 output is needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:8
Finding

Unpinned and Ecosystem-Mismatched Dependencies

Content
View full analysis
=3.5.0", "numpy": ">=1.20.0", "pillow": ">=8.0.0" } ``` `SKILL.md:49-56`: ```bash pip install matplotlib numpy pillow # For MP4 support: # macOS: brew install ffmpeg # Ubuntu: sudo apt install ffmpeg ``` ### Technical Analysis The implementation is written in Python and imports `matplotlib`, `numpy`, and Pillow-related functionality. However, these dependencies are declared in the npm `dependencies` section of `package.json`. Consequently, `npm install` resolves packages from the npm ecosystem rather than installing the Python packages required by the script. This ecosystem mismatch creates dependency-confusion and package-substitution risk: identically named npm packages are not necessarily the reviewed Python components and may contain npm lifecycle scripts that execute during installation. The Python installation instructions also use unconstrained package names, while the npm declarations permit every future version above a minimum threshold. The project provides neither a lockfile nor integrity hashes. Dependency resolution can therefore change after review, allowing a subsequently compromised release or transitive dependency to enter the installation process. No evidence was found that the currently inspected project deliberately introduces a malicious dependency. The vulnerability is the unsafe and ambiguous dependency acquisition model. ### Attack Path 1. A user obtains the skill and follows its installation process or runs `npm install` based on the included `package.json`. 2. npm resolves `matplotlib`, `numpy`, and `pillow` from the npm registry instead of obtaining the intended Python dis ...[truncated 1245 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

pip install matplotlib numpy pillow

For MP4 support:

macOS: brew install ffmpeg

Ubuntu: sudo apt install ffmpeg

text

## Example

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sets global matplotlib font preferences to a specific list of Chinese-capable fonts and disables unicode minus handling behavior without any user opt-in or explanation of a locale constraint. This is a natural-language locale policy issue because the implementation imposes a language/locale preference rather than making it configurable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.