Back to skill

Security audit

流体网络求解器

Security checks for vulnerabilities and agentic risk

Overview

This is a local fluid-network calculator with packaging and input-size weaknesses, but no hidden data access, persistence, or exfiltration behavior was found.

Install only in an environment with normal dependency review and resource limits. Pin the dependencies, remove the bundled venv from distribution, and avoid sending untrusted or very large TOML networks until input-size limits are added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/solver.py:53
Finding

Unbounded Dense Matrix Allocation Enables Resource-Exhaustion Denial of Service

Content
View full analysis
Remediation
View remediation
MAX_UNKNOWN_NODES: raise ValueError( f"Network contains {n_unknown} unknown-pressure nodes; " f"the maximum is {MAX_UNKNOWN_NODES}" ) ``` The actual threshold should be selected from measured memory and latency budgets. A sparse solver should still be combined with hard limits because sparse inputs can also be crafted to consume excessive resources. ]]>

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Future Releases

Content
View full analysis
Remediation
View remediation
\ --hash=sha256: tomli== \ --hash=sha256: click== \ --hash=sha256: ``` Versions and hashes should be generated from packages actually tested and approved by the project rather than selected solely from this example. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (20)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents the command description, argument help text, error messages, and output labels in Chinese only. That imposes a specific language on all users without offering a locale option or documenting a justified region-specific constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-visible strings for failures and analysis output are hard-coded in Chinese across the CLI flow. Because the skill does not offer language choice or explain a justified locale restriction, this is a natural-language policy issue rather than a code-security defect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The inline comment on L140 says 'quadratic simplified handling', which implies behavior distinct from the linear case. However, L141 uses the exact same formula as the linear branch on L139, so the documentation/comment suggests special quadratic treatment that the implementation does not actually provide.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire schema documentation is written in Chinese, including the title and all field descriptions, with no indication that this is a region-specific or Chinese-only skill. That creates a natural-language policy concern because it effectively imposes a language choice on users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language description and usage guidance are partly written in Chinese with an English cue phrase, but the skill does not state that language is optional or user-selectable. This can amount to an implicit language policy constraint for users who do not read Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This TOML file contains natural-language descriptions only in Chinese ("正常工况", "源压力降低") with no indication that the skill is region-specific or that users can opt into that locale. Under the language/locale policy rule, hard-coding a specific language without documented choice or justification can be a policy violation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency on numpy is unpinned, which makes builds non-reproducible and allows future installs to pull unexpected versions, including vulnerable or breaking releases. In a security context this creates supply-chain risk because the actual package version deployed cannot be verified or audited reliably.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
numpy
tomli
click

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Numpy has known advisories, and because no version is pinned there is no way to determine whether the installed environment will use a fixed or affected release. This is a real supply-chain verification weakness even if the presence of an exploitable CVE in practice depends on the resolved version and code paths used.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The tomli dependency is unpinned, so installations may resolve to different versions over time. This weakens reproducibility and makes it harder to verify whether the deployed package contains known vulnerabilities or incompatible behavior.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
numpy
tomli
click

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The click dependency is unpinned, allowing package resolution to drift to any available release at install time. That increases supply-chain exposure and may introduce vulnerable versions or behavior changes without explicit review.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
numpy
tomli
click

Unverifiable Dependency: click has 1 known advisory(ies) (CVE-2026-7246 (Pallets Click, versions 8.3.2 and below, contain a command injection vulnerabili)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Click has a known advisory and the lack of version pinning prevents verification that deployments avoid affected releases. Because this skill likely exposes a CLI interface, use of a vulnerable click version could be more relevant than in a pure library context, though exploitability still depends on the exact installed version and usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function docstring is written entirely in Chinese and states the behavior in that language, with no indication that users may choose another language or locale. This can violate a language/locale policy when a skill implicitly constrains interaction language without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file uses Chinese in docstrings and comments (for example at L11-L12), which imposes a specific language context in the skill implementation without any visible user choice or documented locale justification. Under the policy, language-specific behavior should be opt-in or clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The docstrings and inline comments are written entirely in Chinese, which can impose a language choice on users or maintainers without offering any language/locale option. The policy specifically calls for flagging language or locale constraints when they are forced without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code contains natural-language docstrings and comments exclusively in Chinese, including the function description at L05 and operational comments later in the file. Per the policy, forcing a specific language without user opt-in can be a locale/language policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file includes natural-language content in Chinese, including docstrings and a printed warning, with no indication that the skill is region-specific or that users can opt into another language. Under the policy rule for language/locale, this is a natural-language constraint that may exclude users without documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The print statement emits a warning only in Chinese, which is a direct user-facing language choice without opt-in or explanation. This matches the language/locale policy concern because the skill does not offer an alternative language or justify the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code includes user-facing natural language strings in Chinese only, including the scenario description and printed labels. The file provides no indication that the user can choose a language or that the locale restriction is intentional and justified, which fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file contains user-facing natural-language content only in Chinese, including the explanatory comment and the scenario description string. This imposes a specific language/locale without any opt-in or indication that the skill is intentionally region-specific, which can conflict with language-choice policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal, suspicious.insecure_tls_verification (+1 more)

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/arrayprint.py:1568

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/tests/test_arrayprint.py:339

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/tests/test_dtype.py:1070

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/tests/test_multiarray.py:1663

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/tests/test_records.py:170

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/tests/test_scalarmath.py:618

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/tests/test_simd.py:244

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/tests/test_umath_accuracy.py:77

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/_core/tests/test_umath.py:512

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/f2py/auxfuncs.py:632

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/f2py/capi_maps.py:159

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/f2py/crackfortran.py:1329

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/random/tests/test_extending.py:111

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/testing/_private/extbuild.py:78

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/tests/test_lazyloading.py:26

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/tests/test_public_api.py:405

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/numpy/typing/tests/test_typing.py:205

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/pip/_vendor/packaging/licenses/__init__.py:100

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/Lib/site-packages/pip/_vendor/pygments/formatters/__init__.py:91

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/Lib/site-packages/pip/_internal/network/auth.py:94

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/Lib/site-packages/pip/_vendor/requests/adapters.py:257

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/Lib/site-packages/pip/_vendor/requests/sessions.py:322

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/Lib/site-packages/pip/_vendor/urllib3/connection.py:423

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/Lib/site-packages/pip/_vendor/urllib3/connectionpool.py:991

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/Lib/site-packages/pip/_vendor/urllib3/contrib/_securetransport/low_level.py:231

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/Lib/site-packages/pip/_vendor/urllib3/contrib/socks.py:102

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/numpy/_core/multiarray.py:112

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/numpy/_core/tests/test_overrides.py:294

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/numpy/lib/_ufunclike_impl.py:16

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/pip/_internal/network/session.py:311

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/pip/_vendor/truststore/_macos.py:371

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/pip/_vendor/truststore/_windows.py:458

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/pip/_vendor/urllib3/connection.py:454

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/pip/_vendor/urllib3/contrib/pyopenssl.py:113

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/pip/_vendor/urllib3/contrib/securetransport.py:794

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/Lib/site-packages/pip/_vendor/urllib3/util/ssl_.py:140

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/_core/strings.py:570

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/_core/tests/test_arrayprint.py:332

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/_core/tests/test_defchararray.py:820

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/_core/tests/test_longdouble.py:360

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/_core/tests/test_multiarray.py:4626

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/_core/tests/test_regression.py:2573

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/lib/tests/test_format.py:573

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/lib/tests/test_io.py:707

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/Lib/site-packages/numpy/random/tests/test_generator_mt19937.py:972