Back to skill

Security audit

Circos Plot Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated plotting purpose, but its dependency and input-handling/documentation gaps need Review before installation.

Install only after replacing the ambiguous 'yaml' requirement with a reviewed pinned dependency such as the intended YAML library. Use trusted CSV/YAML inputs, choose a fresh output directory, avoid elevated privileges, and run optional Circos rendering in a constrained working directory because generated configuration is not strictly validated.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Ambiguous and Unpinned YAML Dependency Creates Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
``` 2. Select a currently supported version after reviewing its published security advisories. 3. Use a lockfile or hash-checked requirements file, for example: ```text PyYAML== --hash=sha256: ``` 4. Install dependencies with hash enforcement: ```bash pip install --require-hashes -r requirements.txt ``` 5. Use a trusted package index and prevent unreviewed fallback indexes. 6. Generate a software bill of materials and scan dependencies in CI. 7. Update `SKILL.md`, which currently claims that no external packages are required. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:292
Finding

Untrusted YAML and CSV Values Are Injected into Circos Configuration Syntax

Content
View full analysis
str: """Generate custom tracks from configuration.""" tracks_config = self.config.get("tracks", []) tracks = [] for i, track in enumerate(tracks_config): track_type = track.get("type", "histogram") track_file = track.get("file", f"data/track_{i}.txt") color = track.get("color", f"color{i % len(self.colors)}") if track_type == "histogram": tracks.append(f""" type = histogram file = {track_file} r1 = {0.95 - i*0.15}r r0 = {0.80 - i*0.15}r fill_color = {color} stroke_color = black stroke_thickness = 1 """) elif track_type == "link": tracks.append(f""" file = {track_file} radius = {0.75 - i*0.1}r color = {color} thickness = 2 """) return "\n".join(tracks) ``` YAML values overwrite the configuration after argparse has performed type and choice validation: ```python if args.config: import yaml with open(args.config, 'r') as f: config.update(yaml.safe_load(f)) ``` The generated configuration is optionally passed to Circos: ```python if args.render: import subprocess try: result = subprocess.run( ["circos", "-conf", config_path], capture_output=True, text=True, cwd=args.output ) ``` Other untrusted values are also interpolated without escaping: ```python ...[truncated 3390 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Earlier sections describe the skill as generating Circos configuration files, writing multiple text config/data artifacts, and optionally rendering PNG/SVG via Circos (L0396-L0479). Later, the Parameters, Risk Assessment, Prerequisites, and Success Metrics sections instead describe a simpler SVG-generating script with --output as an SVG file path and claims such as "Creates valid SVG output files," which conflicts with the documented config-generation-plus-optional-rendering behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes this skill as generating Circos configuration files for visualization. However, the optional --render path invokes an external program using subprocess.run, adding command execution capability that is not necessary to merely generate configuration files and is not stated in the manifest description.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/main.py (reported line 498)May include surrounding context.

python
if args.render:
        import subprocess
        try:
            result = subprocess.run(
                ["circos", "-conf", config_path],
                capture_output=True,
                text=True,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file explains that the skill generates configuration files and later examples show writing outputs such as configs, data files, and images. Although file creation is central to the skill, the description does not include an explicit user-facing warning that running it will create or overwrite files in output locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill uses Chinese terms '上游' and '下游' in user-facing documentation while the rest of the document is in English. This introduces a language-specific presentation choice without indicating user opt-in or offering an alternative language setting.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The SKILL.md risk assessment states "No external API calls" and the security checklist says "No network connections" (L1016, L1029), yet the document explicitly references external URLs for Circos documentation and Bioconda resources. This is a documentation-level contradiction about whether network access is involved, even though it appears limited to referenced resources rather than core execution behavior.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency is specified without any version pinning, which makes installs non-reproducible and allows future upstream releases to change behavior or introduce vulnerable code unexpectedly. In a plotting skill that may be installed automatically in agent environments, this increases supply-chain risk because a later package version could break the skill or introduce exploitable issues without any repository change.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
yaml

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code creates output directories and writes generated files such as circos.conf into the user-specified output path, but there is no explicit warning that existing files may be created or overwritten. For code files, file writes should have some visible disclosure unless the behavior is clearly communicated; here the prints occur only after generation and do not warn beforehand.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function creates the output directory and writes sample CSV files into it, but the only disclosure is a print after the file is already created. This is a safety-relevant file write operation lacking advance user warning or overwrite notice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.