Back to skill

Security audit

Adobe - Agentic Control of Graphic Software

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Adobe desktop-app automation helper, with the main caution that its optional Flue install command uses an unpinned third-party package.

Install only if you want an agent to control desktop applications through Flue. Review the Flue project first, prefer a pinned/verified version in an isolated environment, and only approve app actions that are specific and reversible enough for your documents or projects.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Package Installation and Setup

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16 and FLUE.md:72
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: Medium

Relevant Snippets:

SKILL.md:16:

markdown
4. **If Flue is not installed:** tell the human. The install command is `pip install flue && flue setup`. Do not install without explicit approval in the current session.

FLUE.md:72:

markdown
If Flue appears relevant but is not available on the machine, tell your human as much. Inspect the project at `https://github.com/SFKislev/flue` (PyPI: `https://pypi.org/project/flue`). Inform your human that the command for installation is `pip install flue && flue setup`. Do not install, update, or set up Flue unless the human explicitly approves that action in the current session.

Technical Analysis

The documented installation command retrieves the current flue release from the package index without specifying a reviewed version, enforcing package hashes, or validating the resolved artifact. It then immediately invokes the package-controlled flue setup command.

User approval reduces the likelihood of an unexpected installation but does not address dependency integrity. If the upstream project, maintainer account, distribution infrastructure, or a newly published package release is compromised, the command can retrieve and run code that was not present during this audit. The audited project contains only documentation and does not include the Flue package implementation, a lockfile, artifact hashes, or other material that would permit verification of the installed code.

Attack Path

  1. An attacker compromises the upstream package, its publication credentials, or a future package release.
  2. The attacker publishes a modified package under the expected flue package name.
  3. A user approves installation after following the Skill documentation.
  4. `pip insta ...[truncated 970 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin Flue to a specifically reviewed version instead of installing the latest release:
    shell
    python -m pip install "flue==<reviewed-version>"
    
  2. Download and inspect the resolved wheel before installation.
  3. Verify the package with an approved SHA-256 hash, such as through a requirements file using --require-hashes.
  4. Separate installation and setup into distinct commands so users can review the installed files and setup behavior before execution.
  5. Install into an isolated virtual environment and run with the minimum required user privileges.
  6. Document the expected package publisher, release version, artifact hash, and source revision.
  7. Avoid elevated shells unless a reviewed adapter explicitly requires elevation.
  8. Periodically reassess the pinned release and update only after reviewing its source and setup behavior.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.