Back to skill

Security audit

pytest-test-master

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language pytest reference CLI that prints local guidance and examples, with no evidence of hidden execution, data theft, persistence, or privilege escalation.

Install only if Chinese-language pytest guidance is acceptable. For stronger supply-chain hygiene, run it in an isolated Python environment and pin dependency versions instead of using bare pip install commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:22
Finding

Unpinned Python Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Locations:

  • README.md:22
  • clawhub.json:27
  • pytest_master.py:1374

Vulnerability Type: Uncontrolled third-party dependency resolution
Risk Level: Medium

Vulnerable Code

README.md:22:

bash
pip install pytest

clawhub.json:27:

json
"installation": "pip install pytest",

pytest_master.py:1374:

yaml
- run: pip install pytest pytest-cov

Technical Analysis

The installation instructions and generated CI example install pytest and pytest-cov without exact version constraints or package hashes. Consequently, the packages and their transitive dependencies are resolved from mutable upstream repositories at installation time.

This does not demonstrate that any currently referenced package is malicious. However, it prevents reproducible dependency resolution and makes the installation dependent on whichever releases are available when the command runs. If an upstream release or transitive dependency is compromised, the affected package could execute code during installation or later when imported or invoked.

The risk is especially relevant to the CI example because CI runners may have access to repository contents, workflow tokens, environment variables, build artifacts, and other job-scoped credentials.

Attack Path

  1. An attacker compromises an upstream package release, a transitive dependency, or the package publication process.
  2. A developer runs the documented pip install pytest command, or a CI workflow adopts the generated pip install pytest pytest-cov example.
  3. Pip resolves the compromised release because no reviewed version or hash is enforced.
  4. Malicious package code executes during installation, import, plugin discovery, or test execution.
  5. The code operates with the permissions of the developer account or CI runner and may access files, environment variables, source code, artifacts, and network ...[truncated 702 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency file with exact versions, for example:

    text
    pytest==<reviewed-version>
    pytest-cov==<reviewed-version>
    
  2. Generate and verify hashes for all direct and transitive dependencies, then install with hash enforcement:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Use a lock-generation tool such as pip-tools to produce a fully resolved, reproducible dependency set.

  4. Update README.md, clawhub.json, and the CI example in pytest_master.py so they all reference the same locked dependency file rather than installing unconstrained package names.

  5. Review dependency updates through controlled pull requests and use automated vulnerability scanning before merging them.

  6. Run dependency installation and tests in an isolated, least-privileged environment. Avoid exposing unnecessary secrets to dependency installation steps, particularly in CI.

  7. For the adjacent GitHub Actions examples, pin third-party actions to reviewed immutable commit SHAs rather than mutable version tags.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is written in Chinese and frames the skill as a Chinese-language offering, but the README does not provide any user choice of language or explain a region-specific constraint. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all user-facing instructions, examples, and command descriptions in Chinese only. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can exclude users and violates language-choice expectations unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written entirely in Chinese and does not indicate that the skill supports other languages or that Chinese is a required locale. This can violate a language/locale policy when users are not given an explicit language choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing descriptive text entirely in Chinese in the module docstring and throughout the returned content strings. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation, and the file does not document that the skill is intentionally region-specific or offer alternative locales.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · pytest_master.py (reported line 504)May include surrounding context.

python
result = fetch_user(1)
    assert result["name"] == "Alice"
    mock_get.assert_called_once_with(
        "https://api.example.com/users/1"
    )

# 方式二:patch 上下文管理器(更直观)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and user-facing CLI help text are written in Chinese, indicating the skill is presented in a fixed language. The file does not provide any visible mechanism for users to choose another language or opt into this locale, which fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The parser description, epilog, command descriptions, and examples are all presented in Chinese, making the command-line UX fixed to one language. Because no language choice or opt-in is offered in this file, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script's comments and user-facing echo messages are written in Chinese throughout, which imposes a specific language on users. Under the policy, language constraints should be optional or explicitly justified; this file provides neither a language selection mechanism nor a documented reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.