Back to skill

Security audit

Life Science Database Query

Security checks for vulnerabilities and agentic risk

Overview

This biology database skill is largely purpose-aligned, but its helper scripts allow overly broad web requests and raw-response writes to arbitrary files, so it should be reviewed before installation.

Install only in a constrained environment. Do not let untrusted prompt content choose base_url, absolute path URLs, headers, bodies, or raw_output_path values; prefer fixed public database origins, restrict network egress, confine raw outputs to a dedicated directory, and pin dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skills/alphafold-skill/scripts/rest_request.py:63
Finding

Caller-Controlled URLs Enable Server-Side Request Forgery Across Generic REST Clients

Content
View full analysis
str: if path.startswith(("http://", "https://")): return path ...[truncated 3258 chars]
Remediation
View remediation
str: if not isinstance(path, str) or not path.strip(): raise ValueError("A relative API path is required.") if urlsplit(path).scheme or urlsplit(path).netloc: raise ValueError("Absolute URLs are not permitted.") url = urljoin("https://alphafold.ebi.ac.uk/api/", path.lstrip("/")) parsed = urlsplit(url) port = parsed.port or 443 if (parsed.scheme, parsed.hostname, port) != ALLOWED_ORIGIN: raise ValueError("Destination origin is not allowed.") return url ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
skills/alphafold-skill/scripts/rest_request.py:136
Finding

Unrestricted Raw-Output Paths Permit Arbitrary File Overwrite

Content
View full analysis
str: path = Path(raw_output_path or f"/tmp/{_service_name(base_url)}-raw.{suffix}") path.parent.mkdir(parents=True, exist_ok=True) path.write_text(raw_output, encoding="utf-8") return str(path) ``` The Clin ...[truncated 3163 chars]
Remediation
View remediation
Path: if not filename or Path(filename).name != filename: raise ValueError("Only a plain output filename is permitted.") OUTPUT_ROOT.mkdir(mode=0o700, parents=True, exist_ok=True) candidate = (OUTPUT_ROOT / filename).resolve(strict=False) if candidate.parent != OUTPUT_ROOT: raise ValueError("Output path escapes the approved directory.") return candidate def write_new_file(path: Path, content: str) -> None: flags = os.O_WRONLY | os.O_CREAT | os.O_EXCL if hasattr(os, "O_NOFOLLOW"): flags |= os.O_NOFOLLOW fd = os.open(path, flags, 0o600) with os.fdopen(fd, "w", encoding="utf-8") as handle: handle.write(content) ``` ]]>

T08 · Insecure Dependencies

Warning
Location
skills/ncbi-blast-skill/SKILL.md:53
Finding

Documentation Recommends Installing an Unpinned Runtime Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (220)

Tainted flow: 'payload' from requests.get (line 304, network input) → subprocess.run (code execution)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.

Content

Scanner excerpt · skills/locus-to-gene-mapper-skill/scripts/map_locus_to_gene.py (reported line 329)May include surrounding context.

python
limitations.append(f"Missing skill script: {script_path}")
        return None
    try:
        proc = subprocess.run(
            [sys.executable, str(script_path)],
            input=json.dumps(payload),
            text=True,

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot and router across many biology-related sub-skills. The supplied code chunk does not implement such research-routing or life-sciences-specific behavior; instead, it is a generic HTTP client utility. It can contact arbitrary services, submit GET or POST requests, process JSON/text responses, and write raw outputs to /tmp or another path. While such a utility could support a life-sciences skill internally, this chunk by itself exposes broader, undeclared capabilities and lacks the claimed domain-specific primary purpose. Therefore this is a meaningful description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a specialized life-sciences research copilot/router spanning many scientific subdomains and public databases. The supplied code does not implement life-sciences reasoning, routing among sub-skills, database-specific logic, or domain constraints. Instead, it is a generic reusable REST request wrapper that can call essentially any HTTP endpoint with configurable method, headers, params, and body, then parse and summarize the response. This is a materially different primary purpose and includes broader undeclared capabilities such as arbitrary network access and optional raw-response file output. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot and router over public biology data sources. The supplied code does not implement life-sciences logic, research routing, source selection, or any biology-specific functionality. Instead, it is a general-purpose HTTP client/helper that can call essentially any URL with configurable method, headers, params, and body, then parse and truncate the response. It also supports saving raw responses to disk, which is an undeclared capability. While such a REST client could be a supporting component inside a biology skill, this chunk's actual behavior is materially broader and more generic than the declared purpose, and it accesses arbitrary external resources rather than clearly limited life-sciences databases.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot/router composed of many biology-related sub-skills and intended for public database lookups. The supplied code chunk does not implement life-sciences research functionality, routing logic, database-specific behavior, or any biology-focused processing. Instead, it is a reusable generic REST requester that can contact arbitrary endpoints, issue GET or POST requests with custom parameters/headers/bodies, parse responses, and optionally write raw output to disk. Those are materially broader and different capabilities than the declared purpose, so this is a clear description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot and router across many biological data sources. The supplied code chunk does not implement that purpose directly; it is a reusable generic REST helper. It can call essentially any HTTP endpoint via configurable base_url/path and supports custom headers, query params, POST bodies, response parsing, record extraction, and raw-output persistence. While such a helper could support a life-sciences skill, its actual behavior is materially broader and more generic than the declared purpose, and it includes undeclared capabilities like arbitrary endpoint access and file output. Therefore this chunk does not accurately match the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description portrays a general life-sciences research skill suite and router spanning many sub-skills and public databases. The supplied code chunk, however, is narrowly scoped: it only queries the CIViC GraphQL API at civicdb.org, processes the response, and can optionally save raw output to disk. That is a materially different primary purpose from a broad research-router/copilot description. The filesystem write behavior is also not mentioned in the declaration. While CIViC is relevant to life sciences, this code represents one concrete sub-skill with specific external access and output behavior, not the broadly described default entry point.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive life-sciences research copilot/router spanning many domains (genetics, genomics, chemistry, literature, clinical evidence, public study discovery, etc.) and many modular sub-skills. The supplied code chunk, however, is only a compact helper for the ClinicalTrials.gov v2 API. Its behavior is limited to fetching studies, metadata, enums, search areas, and stats from ClinicalTrials.gov, with pagination and optional raw-response saving. This is a materially narrower and different primary purpose than the declared broad multi-skill research copilot/default router. While ClinicalTrials.gov fits one small part of the declared ecosystem (public study discovery), this code alone does not match the breadth or routing function claimed by the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a general-purpose life-sciences research copilot/router covering many scientific domains and public databases. The supplied code chunk does not implement such a router or broad copilot behavior; instead, it is a single-source helper dedicated to ClinVar Clinical Tables and NCBI Variation API queries for variant-related identifiers. This is a materially narrower primary purpose than declared. Additionally, the code can save raw responses to /tmp or a caller-specified path, which is an extra capability not reflected in the description. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents this as a specialized life-sciences research copilot/router spanning many biological data domains. The supplied code chunk instead implements a domain-agnostic REST request utility. It can contact arbitrary URLs, issue GET/POST requests, process generic JSON/text responses, and optionally write raw outputs to disk. Those are broader technical capabilities than the declared purpose and are not inherently limited to life-sciences resources. While such a helper could support a life-sciences skill, this code chunk by itself does not reflect the claimed primary purpose and exposes undeclared generic network and file-output behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk does not implement a life-sciences research copilot or a router across domain-specific sub-skills. Instead, it is a reusable generic REST request script that can query arbitrary endpoints via GET/POST, process JSON/text, infer record lists, and optionally save raw output locally. While such a helper could support life-sciences lookups, its actual behavior is materially broader and more generic than the declared purpose, and it includes undeclared file-writing capability. This is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description is for a high-level life-sciences research copilot composed of many domain-specific sub-skills and a default routing function for broad biological questions. The supplied code does not implement that described behavior. Instead, it is a reusable generic REST request helper with flexible network access and output formatting. It can call arbitrary services, not specifically public life-sciences databases, and it includes capability to save raw outputs to disk. While such a utility could support one sub-skill internally, this code chunk by itself is materially more generic than the declared purpose and lacks the described research-router or scientific reasoning functionality. Therefore this chunk does not accurately represent the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot/router composed of many biology-focused sub-skills. This code chunk does not implement life-sciences reasoning, routing, or any specific public database integration. Instead, it is a generic reusable HTTP client that can query essentially any specified endpoint via GET or POST, pass custom headers and request bodies, parse responses, and save raw outputs to /tmp or a caller-specified path. That is a materially broader and different capability than the declared purpose. While such a client could support a life-sciences skill internally, the code itself exposes undeclared generic network and file-write capabilities and lacks domain-specific constraints, so the description does not accurately represent the behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for an overall life-sciences research copilot/router covering many scientific domains and sub-skills. The supplied code chunk does not implement that broad orchestration behavior. Instead, it is a transport/helper script that validates request payloads, performs HTTP GET/POST requests, auto-detects JSON, extracts records by path, truncates output, optionally saves raw responses, and includes eQTL Catalogue-specific query normalization. This makes the code's actual purpose materially narrower and different from the declared purpose. While the script is still related to life-sciences/public-database access, it is not itself the described general research copilot or router, so this should be flagged as a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot and router over many biology-related sub-skills and public databases. The supplied code chunk, however, is not specific to life sciences at all: it is a generic REST request utility. It can contact arbitrary URLs, send custom headers and request bodies, parse and compact responses, and write raw outputs to disk. Those are materially broader capabilities than the declared description, especially unrestricted network access and filesystem output. While such a helper could be used as supporting infrastructure for life-sciences lookups, the actual behavior shown here is not accurately represented by the description because it exposes a general-purpose HTTP client rather than a narrowly scoped life-sciences database skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a domain-specific life-sciences research copilot and router for public biomedical database queries. The code shown does not implement research routing, life-sciences-specific logic, database-specific integrations, or any of the described sub-skill behavior. Instead, it is a reusable generic REST request wrapper that can call essentially any HTTP endpoint with configurable headers, params, and bodies, then summarize or persist the response. That is a materially broader and different capability than the declared purpose. While such a helper could support a biomedical skill, this code chunk itself is not accurately represented by the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot and router across many biology-related sub-skills and public databases. The supplied code chunk does not implement life-sciences reasoning, routing, database-specific integrations, or any biology-focused functionality. Instead, it is a reusable generic REST request utility that can call arbitrary endpoints with configurable parameters and optionally save raw output locally. That is a materially broader and different capability than the declared purpose, and it accesses generic network resources rather than specifically life-sciences public databases. While such a client could support the declared system, this code chunk by itself is mismatched with the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad, default-entry research copilot/router spanning many life-sciences domains and modular sub-skills. The supplied code chunk does not behave like a general copilot or router. It performs one specialized task: mapping GWAS loci to candidate genes using deterministic evidence aggregation from specific genetics resources. While this specialized function plausibly belongs within the larger life-sciences bundle, the code itself is materially narrower than the declared purpose and lacks routing behavior. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description is for a domain-specific life-sciences research copilot and router spanning many biology-related sub-skills and public databases. The supplied code chunk does not implement life-sciences reasoning, routing, database-specific logic, or metabolomics-specific behavior. Instead, it is a reusable generic REST request utility that can call arbitrary URLs with user-supplied parameters and headers, parse responses, and save raw output locally. That is a materially different primary purpose and exposes undeclared generic network/file-output capabilities. While such a client could be supporting infrastructure for a research skill, this code chunk itself is not accurately represented by the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for a broad life-sciences research copilot composed of many domain-specific sub-skills and a router for public biological databases. The provided code chunk does not implement life-sciences reasoning, routing, database-specific logic, or any biology-focused functionality. Instead, it is a generic HTTP client helper that can call arbitrary endpoints with configurable URLs, headers, params, and POST bodies, parse responses, and optionally write raw output to disk. That is a materially different primary purpose and includes undeclared capabilities such as arbitrary network access and filesystem output. While such a client could support a life-sciences skill internally, this code chunk by itself is not accurately represented by the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents the skill as a general life-sciences research copilot and default entry point for broad or ambiguous requests spanning many biological domains and public databases. The supplied code chunk, however, is a single-purpose utility for one data source: the NCBI PMC Open Access endpoint. It validates input, issues a GET request, parses XML, extracts/compacts records, and can optionally save raw XML locally. This is materially narrower than the declared purpose and does not exhibit routing/orchestration behavior across multiple sub-skills or databases. The optional file-write behavior is also undeclared. Therefore the code does not accurately represent the broad declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot and router over public biological/clinical databases. The supplied code chunk does not implement life-sciences reasoning, routing across sub-skills, or any PharmGKB-specific/database-specific logic. Instead, it is a generic REST request wrapper that can call arbitrary endpoints, include arbitrary headers and bodies, parse responses, and optionally persist raw output to disk. That makes its actual capability materially broader and more infrastructure-oriented than the declared purpose. While such a helper could support a research skill, on its own this code exposes undeclared network and file-output capabilities and does not match the stated primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a life-sciences research copilot composed of modular public-database lookup skills. However, this code chunk implements a reusable generic REST requester rather than logic tied to life-sciences data, ProteomeXchange, or any specific scientific source. It can contact arbitrary URLs with custom headers and payloads, which is a materially broader capability than a narrowly described research sub-skill. While a generic HTTP helper could support such a skill internally, this implementation itself exposes undeclared general network access and local file output behavior, making the code's actual behavior broader and not accurately represented by the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk does not implement a life-sciences research copilot or routing behavior. Instead, it is a domain-agnostic HTTP client utility for making arbitrary REST requests and compacting responses. While such a helper could support a PubChem or broader life-sciences skill, on its own it exposes undeclared generic networking capability to any base_url/path and optional local file output. That is materially broader and lower-level than the declared purpose of a general life-sciences research copilot with modular sub-skills.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a domain-specific life-sciences research copilot and router over many public scientific sub-skills/databases. The supplied code chunk instead implements a reusable generic REST request wrapper. It can call essentially any HTTP endpoint via configurable base_url/path, headers, params, and bodies, then summarize or save the response. There is no visible life-sciences-specific logic, no routing across 50 sub-skills, no genetics/pathway/protein/clinical functionality, and no restriction to public research databases. This is a materially different primary purpose and exposes broader undeclared network/file-output capabilities, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
skills/eqtl-catalogue-skill/scripts/test_rest_request.py:12

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
skills/locus-to-gene-mapper-skill/scripts/test_map_locus_to_gene.py:13

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
skills/ncbi-blast-skill/scripts/test_ncbi_blast.py:19