Back to skill

Security audit

Adme Property Predictor

Security checks for vulnerabilities and agentic risk

Overview

This is a local ADME prediction skill with no hidden network or persistence behavior, but it has unpinned dependencies and overstates model maturity compared with the shipped heuristic script.

Install only in an isolated environment, preferably with pinned and hashed dependencies from a trusted package source. Treat outputs as rough prioritization signals, not validated pharmacokinetic evidence, and require experimental validation before research, regulatory, or clinical decisions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unhashed Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, lines 1-2
Vulnerability Type: Supply-chain exposure through unconstrained dependencies
Risk Level: Medium

Vulnerable Code

text
dataclasses
rdkit

Technical Analysis

The dependency manifest specifies package names without exact versions or integrity hashes. Consequently, each installation may resolve different package releases from the configured package index. This prevents reproducible verification of the dependency set and allows a compromised or unexpectedly changed release to enter the installation process without corresponding changes to the audited project.

The dataclasses package is a backport that is unnecessary when the project requires Python 3.7 or later. Retaining an unnecessary dependency increases the number of external components that must be trusted and monitored.

This finding does not establish that either listed package is currently malicious. The vulnerability is the project's failure to constrain and verify the third-party artifacts it installs.

Attack Path

  1. A user or automated deployment process runs pip install -r requirements.txt.
  2. The package resolver selects the releases available from the configured index at installation time.
  3. An upstream package, distribution artifact, package-index account, or configured index is compromised.
  4. Because the manifest contains neither exact versions nor expected hashes, the compromised artifact can be accepted without modifying this repository.
  5. Malicious package installation or import-time code executes with the privileges of the account running the installation or application.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installer or application account. The resulting access would be limited by that account's operating-system privileges but could include reading or modifying accessible files, altering prediction output, accessing environmen ...[truncated 174 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define and enforce a supported Python version. If Python 3.7 or later is required, remove the unnecessary dataclasses backport.
  2. Pin RDKit and every transitive dependency to reviewed, exact versions in a generated lock file.
  3. Record cryptographic hashes for all distributions and install with pip --require-hashes.
  4. Generate lock files in a controlled environment using a trusted package index, and prevent fallback to unapproved indexes.
  5. Review dependency updates through a controlled change process that includes vulnerability scanning, provenance verification, and regression testing.
  6. Install dependencies as an unprivileged user inside an isolated virtual environment or container.
  7. Example hardened workflow:
bash
python -m pip install pip-tools
pip-compile --generate-hashes requirements.in
python -m pip install --require-hashes -r requirements.txt

The generated lock file should be committed after its exact versions and hashes have been reviewed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language headings for related skills use Chinese terms ("上游" and "下游") inside an otherwise English skill description. This imposes a locale/language choice on users without opt-in and may conflict with organizational language consistency expectations.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The dependency is unpinned, so installations may resolve to different versions over time, including versions with newly introduced vulnerabilities or breaking changes. In a scientific/cheminformatics skill, this mainly creates supply-chain and reproducibility risk rather than direct exploitability, but it is still a real security weakness.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
dataclasses
rdkit

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The rdkit dependency is unpinned, allowing future installs to pull different releases with potentially vulnerable transitive dependencies or unsafe package substitutions. Because this skill processes chemical data using a complex native/scientific library, version drift can increase supply-chain risk and may expose consumers to vulnerable builds or malicious package poisoning if installation sources are not tightly controlled.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
dataclasses
rdkit

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest and CLI imply the skill can evaluate specific ADME subsets, yet the predict method ignores its properties parameter and unconditionally calculates absorption, distribution, metabolism, excretion, and overall recommendation fields. This is a behavior mismatch because the implemented operation is broader than the exposed intent communicated by the interface and documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.