Back to skill

Security audit

FEP Alternative

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent scientific workflow, but it gives the agent overbroad network and file-write power and relies on mutable remote instructions to generate or run authenticated SciMiner calls.

Review before installing. This skill should only be used in a tightly sandboxed environment with outbound network allowlists for SciMiner and RCSB, no access to unrelated local files, and a scoped SciMiner token. Do not let it run code copied from remote Markdown or save raw responses to arbitrary paths.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:87
Finding

Mutable Remote Documentation Is Used to Generate and Run Invocation Code

Content
View full analysis
`PBCNet 2.0_api_doc.md` - `Gnina` -> `Gnina_api_doc.md` The agent MUST: 1. Resolve the selected SciMiner tool's Markdown file and read it before every invocation. 2. Never invent `provider_name`, `tool_name`, parameter names, enum values, upload-field names, content type, or submission flow from memory. 3. Extract and follow the selected SciMiner doc section's exact: - Base URL - API endpoint - Content-Type - Authentication header - Tool Name - Method - Parameter table, including required fields and enum values - File-upload instructions and example code ``` ```markdown 13. Write or run invocation code directly from the selected Markdown docs' base-information block, parameter table, file-upload instructions, and example code. Do not apply a shared invocation template or local registry abstraction in this skill. ``` ```markdown - Use the selected SciMiner Markdown docs under `https://sciminer.tech/tool_api_files/` as the authoritative source for payload construction and invoke-method details. - Read the SciMiner API key from `~/.config/sciminer/credentials.json` and send it as the `X-Auth-Token` header. ``` ### Technical Analysis The Skill makes mutable Markdown hosted on an external server the authoritative source for request endpoints, authentication behavior, upload procedures, and example code. It then explicitly instructs the Agent to ...[truncated 2458 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
rcsb-pdb-skill/scripts/rest_request.py:63
Finding

Generic REST Client Allows Server-Side Request Forgery

Content
View full analysis
str: if path.startswith(("http://", "https://")): return path return base_url.rstrip("/") + "/" + path.lstrip("/") ``` ```python def parse_input(payload: Any) -> dict[str, Any]: if not isinstance(payload, dict): raise ValueError("Input must be one JSON object.") base_url = _require_str("base_url", payload.get("base_url"), required=True) path = _require_str("path", payload.get("path"), required=True) method = (_require_str("method", payload.get("method")) or "GET").upper() if method not in {"GET", "POST"}: raise ValueError("`method` must be GET or POST.") json_body = payload.get("json_body") form_body = payload.get("form_body") if json_body is not None and form_body is not None: raise ValueError("Provide only one of `json_body` or `form_body`.") response_format = ( _require_str("response_format", payload.get("response_format")) or "auto" ).lower() if response_format not in {"auto", "json", "text"}: raise ValueError("`response_format` must be auto, json, or text.") return { "base_url": base_url, "path": path, "method": method, "params": _require_object("params", payload.get("params")), "headers": _require_object("headers", payload.get("headers")), "json_body": json_body, "form_body": _require_object("form_body", form_body) if form_body is not None else None, "record_path": _require_str("record_path", payload.get("record_path")), "response_format": response_format, "max_items": _require_int("max_items", payload.get("max_items"), 5), "max_depth": _require_int("max_depth", payload. ...[truncated 3387 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
rcsb-pdb-skill/scripts/rest_request.py:137
Finding

Caller-Controlled Raw Output Path Enables Arbitrary File Overwrite

Content
View full analysis
str: path = Path(raw_output_path or f"/tmp/{_service_name(base_url)}-raw.{suffix}") path.parent.mkdir(parents=True, exist_ok=True) path.write_text(raw_output, encoding="utf-8") return str(path) ``` ```python "save_raw": _require_bool("save_raw", payload.get("save_raw"), False), "raw_output_path": _require_str("raw_output_path", payload.get("raw_output_path")), ``` ```python raw_output_path = None if config["save_raw"]: raw_output_path = _save_raw_output( raw_output, config["raw_output_path"], config["base_url"], "json" ) ``` ```python raw_output_path = None if config["save_raw"]: raw_output_path = _save_raw_output( response.text, config["raw_output_path"], config["base_url"], "txt" ) ``` ### Technical Analysis When `save_raw` is enabled, the caller can provide any non-empty string as `raw_output_path`. The path is passed directly to `pathlib.Path`, missing parent directories are created, and `write_text` writes or truncates the selected file. The implementation does not: - Restrict writes to a dedicated output directory. - Canonicalize and validate the resolved path. - Reject absolute paths or `..` traversal. - Reject symbolic links. - Prevent overwriting existing files. - Use exclusive, securely created temporary files. - Apply restrictive file permissions. Because the downloaded HTTP response becomes the file content, this issue can be combined with unrestricted destination selection to place attacker-controlled content at an ...[truncated 1607 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding indicates the skill can perform generic arbitrary HTTP requests, custom headers/body handling, response parsing, and saving raw responses to files, which materially exceeds the declared purpose of running SciMiner/Gnina/PDB workflows. That capability can be abused for SSRF, data exfiltration, unapproved third-party API use, or turning the skill into a general network proxy under the guise of a scientific workflow.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The skill explicitly declares a credential file, which is necessary for operation but still creates sensitive-secret access within the skill context. Because the skill also performs network operations, any prompt-injection, over-broad request handling, or logging mistake could expose or misuse the SciMiner API key.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: FEP-alternative
description: Relative binding free-energy and activity-label prediction workflows using PBCNet 2.0 on SciMiner, with Gnina docking and PDB/database retrieval to complete missing inputs.
credential_files:
   - ~/.config/sciminer/credentials.json
---

# FEP Alternative Skill

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

This instruction tells the agent to read the API key from a local credential file and use it in authenticated requests. That is expected functionality, but it is still a sensitive capability because compromise of the workflow or overly flexible networking could lead to unauthorized use of the credential.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
## Prerequisites

1. Obtain a free SciMiner API key from `https://sciminer.tech/utility`.
2. Store it outside this repository at `~/.config/sciminer/credentials.json`
   with JSON shaped as `{"api_key":"your_api_key_here"}`.
3. For SciMiner calls, read the API key from
   `~/.config/sciminer/credentials.json` and send it as the `X-Auth-Token`

Credential Access

High
Category
Privilege Escalation
Confidence
79% confidence
Finding

The skill couples local secret retrieval with outbound header injection, which is standard but sensitive. In the broader context of a workflow that may fetch remote docs and perform uploads, this expands the chance of accidental credential leakage through malformed requests, debug output, or request reuse.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
2. Store it outside this repository at `~/.config/sciminer/credentials.json`
   with JSON shaped as `{"api_key":"your_api_key_here"}`.
3. For SciMiner calls, read the API key from
   `~/.config/sciminer/credentials.json` and send it as the `X-Auth-Token`
   header.
4. Never print, persist, or store the API key in prompts, logs, or repository
   files. Agents should remember only the credential file path.

Credential Access

High
Category
Privilege Escalation
Confidence
76% confidence
Finding

Although the text says not to print or store the API key, it still establishes direct access to a credential file as part of the skill's behavior. Security guidance reduces risk, but the underlying capability remains sensitive and should be treated as such, especially in a skill with network/file behaviors.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
4. Never print, persist, or store the API key in prompts, logs, or repository
   files. Agents should remember only the credential file path.

If `~/.config/sciminer/credentials.json` is not available or does not contain
an `api_key` field, stop and tell the user to obtain a free SciMiner API key
from `https://sciminer.tech/utility` and store it in that file. Do not try to
complete the task by switching to other tools or services.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

This section again instructs reading the SciMiner API key from a local file for outbound requests. Repetition does not make it malicious, but it confirms the skill's privileged access to secrets, which becomes more dangerous when combined with broad network behaviors identified elsewhere.

Content

Scanner excerpt · SKILL.md (reported line 244)May include surrounding context.

md
- Use the selected SciMiner Markdown docs under
  `https://sciminer.tech/tool_api_files/` as the authoritative source for
  payload construction and invoke-method details.
- Read the SciMiner API key from `~/.config/sciminer/credentials.json` and send
  it as the `X-Auth-Token` header. Do not print or persist the API key in
  prompts, logs, or repository files.
- If `~/.config/sciminer/credentials.json` is missing or does not contain an

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

The skill requires checking the local credential file and using the contained API key, so the capability is real and security-relevant. In context, this is less severe than direct exfiltration logic, but it still increases risk if the skill can be induced to make unintended authenticated requests.

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
- Read the SciMiner API key from `~/.config/sciminer/credentials.json` and send
  it as the `X-Auth-Token` header. Do not print or persist the API key in
  prompts, logs, or repository files.
- If `~/.config/sciminer/credentials.json` is missing or does not contain an
  `api_key` field, stop and tell the user to obtain a free SciMiner API key
  from `https://sciminer.tech/utility` and store it in that file.
- `provider_name` and `tool_name` must exactly match the selected Markdown doc.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill’s stated purpose and implementation scope are materially inconsistent with the broader agent context, introducing a capability mismatch that can cause the agent to access external biological databases outside the user’s expected workflow. In an autonomous or semi-autonomous pipeline, this kind of hidden or misplaced skill can enable unintended data flows, incorrect tool selection, or policy bypass through confusion about what the agent is supposed to do.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares credential access plus behavior that relies on network and likely file handling, but it does not constrain its allowed tools or permissions. In an agent environment, missing tool scoping broadens what the skill can do if prompted maliciously or if the implementation drifts, increasing the blast radius beyond the stated workflow.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
confirmed the rule.
12. Upload required file inputs exactly as described by the selected SciMiner
    Markdown docs and replace local paths with returned `file_id` values.
13. Write or run invocation code directly from the selected Markdown docs'
    base-information block, parameter table, file-upload instructions, and
    example code. Do not apply a shared invocation template or local registry
    abstraction in this skill.

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

This skill explicitly instructs network requests to external RCSB and search endpoints, creating outbound data transmission capability. While the endpoints appear legitimate and the use case is consistent with the skill’s stated purpose, any externally callable request utility can leak user-supplied inputs, sensitive identifiers, or derived research context if invocation is not constrained.

Content

Scanner excerpt · rcsb-pdb-skill/SKILL.md (reported line 8)May include surrounding context.

md
## Operating rules
- Use `scripts/rest_request.py` for all RCSB PDB and Search API calls.
- Use `base_url=https://data.rcsb.org/rest/v1` for core metadata, `https://search.rcsb.org/rcsbsearch/v2` for Search API, and `https://www.rcsb.org` for FASTA downloads.
- Core entry or assembly lookups usually do not need `max_items`; Search API results are better with query pager rows around `10` and `max_items=10`.
- Re-run requests in long conversations instead of relying on older tool output.
- Treat displayed `...` in tool previews as UI truncation, not literal request content.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The documented input schema allows caller-controlled fields such as base_url, path, headers, body content, and raw output options, which materially expands the external request surface beyond fixed safe lookups. If the backing script honors these parameters without strict validation, the skill could be abused for unintended outbound requests, data exfiltration, or retrieval/saving of untrusted content.

Content

Scanner excerpt · rcsb-pdb-skill/SKILL.md (reported line 23)May include surrounding context.

md
- Required fields: `base_url`, `path`
- Optional fields: `method`, `params`, `headers`, `json_body`, `form_body`, `record_path`, `response_format`, `max_items`, `max_depth`, `timeout_sec`, `save_raw`, `raw_output_path`
- Common RCSB patterns:
  - `{"base_url":"https://data.rcsb.org/rest/v1","path":"core/entry/4hhb"}`
  - `{"base_url":"https://search.rcsb.org/rcsbsearch/v2","path":"query","method":"POST","json_body":{"query":{"type":"terminal","service":"full_text","parameters":{"value":"hemoglobin"}},"return_type":"entry","request_options":{"pager":{"start":0,"rows":10}}},"record_path":"result_set","max_items":10}`
  - `{"base_url":"https://www.rcsb.org","path":"fasta/entry/4HHB/download","response_format":"text"}`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · rcsb-pdb-skill/SKILL.md (reported line 34)May include surrounding context.

Execution

bash
echo '{"base_url":"https://data.rcsb.org/rest/v1","path":"core/entry/4hhb"}' | python scripts/rest_request.py

References

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script is a fully generic REST client despite the skill being described as a narrowly scoped scientific retrieval workflow. That mismatch creates capability expansion: an agent using this skill can contact arbitrary services and process unrelated data, increasing the chance of data exfiltration, policy bypass, or misuse beyond the declared purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The URL construction explicitly permits absolute http/https paths, allowing callers to direct requests to arbitrary external hosts rather than only the intended scientific services. In an agent context, this can enable SSRF-like outbound access, exfiltration to attacker-controlled endpoints, and use of the skill as a general network primitive unrelated to the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The helper writes arbitrary response bodies to a file, and execute() enables this whenever save_raw is set. Because this skill performs network requests and may persist returned data under /tmp or a caller-specified path, there is no visible prompt, warning, or disclosure in this code about local data storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code can persist arbitrary remote responses to caller-chosen filesystem locations, including under /tmp by default or any supplied raw_output_path. This creates a local data exposure and storage abuse risk, especially if sensitive responses, oversized content, or misleading files are written for later consumption by other tools or users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.