T09 · Insecure Skill Coding Practices
- Location
scripts/plot_generator.py:82- Finding
Configuration-Controlled Path Traversal Permits Figure Writes Outside the Output Directory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a disclosed scientific plotting workflow, but it needs Review because its config-based plot generator can write files outside the intended output folder and it keeps local copies of uploaded data.
Install only if you are comfortable with a local plotting tool that reads your uploaded datasets and stores copies plus generated reports and figures on disk. Use a dedicated output folder, avoid running configs from untrusted sources, review generated plot_config.json before generation, and prefer a virtual environment with pinned dependencies.
scripts/plot_generator.py:82Configuration-Controlled Path Traversal Permits Figure Writes Outside the Output Directory
docs/installation.md:50Unpinned Mutable Installation Sources Create Supply-Chain Exposure
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
If you need to remove the skill:
rm -rf ~/.claude/skills/pythesis-plot
If using symlink, remove the link (not the original):
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
If you need to remove the skill:
rm -rf ~/.claude/skills/pythesis-plot
If using symlink, remove the link (not the original):
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
If using symlink, remove the link (not the original):
rm ~/.claude/skills/pythesis-plot # Removes symlink only
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## 🎯 What is PyThesisPlot?
PyThesisPlot is a **Claude Code Skill** that teaches AI assistants how to create publication-quality scientific figures from raw data. It provides:
- 📊 **Intelligent Workflow**: Data → Analysis → Recommendations → Confirmation → Figures
- 🎨 **Journal-Ready Output**: 300 DPI, Nature/Science style compliance
The documented trigger is ambiguous about when the skill should activate, which creates unsafe uncertainty for downstream agents deciding whether to load it. Ambiguous activation is risky here because the skill is positioned to inspect uploaded data and create persistent outputs, so accidental invocation can expand data exposure beyond user expectations.
The trigger examples are broad enough to match ordinary requests for charts or figures, which can cause the skill to activate in situations the user did not specifically intend. In a skill that processes uploaded datasets and generates files, overbroad activation increases the chance of unexpected data handling and unintended execution of the plotting workflow.
The README explicitly shows that the original uploaded dataset is copied into a timestamped output directory, but it does not prominently warn users about this persistence behavior or its privacy implications. For research datasets, this can retain sensitive or regulated data in additional locations, increasing the risk of unintended disclosure, mishandling, or later exfiltration.
The trigger description includes broad phrases like asking for plotting or visualization around uploaded files, which can cause the skill to activate in unintended contexts. In a data-processing skill, overbroad activation increases the chance that sensitive user files are analyzed or persisted when the user did not explicitly intend to invoke this workflow.
The documentation states that the workflow saves a renamed copy of the raw dataset along with analysis artifacts and generated code, but it does not warn users about local persistence of potentially sensitive research or participant data. For thesis and scientific use cases, uploaded spreadsheets may contain personal, clinical, or unpublished data, so silent disk retention increases confidentiality and compliance risk.
The skill describes file read/write behavior such as auto-saving uploaded files and generating reports, code, and images into output directories, but it does not declare any explicit tool scope or permissions. This creates an authorization and review gap: an agent or platform may grant broader filesystem access than users or reviewers expect, increasing the risk of unintended file access, overwrites, or data leakage if the implementation is looser than the documentation suggests.
Telling users that they can now simply upload files and ask for charts encourages an always-ready usage pattern and may promote persistent expectation that the skill should activate on generic future requests. In agent environments, this can increase unintended reuse across sessions or tasks, especially when paired with broad trigger phrases.
> ✅ PyThesisPlot skill installed successfully!
>
> You can now upload data files and ask me to create charts.
>
> Try: "Help me create figures from this CSV file"
The installation guide explicitly tells users to test the skill with a very broad natural-language phrase, which increases the chance the skill will activate on ordinary plotting requests beyond the intended narrow context. Broad trigger guidance can cause unintended invocation and context capture, especially in agent ecosystems where activation is phrase-based.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
git clone https://github.com/stephenlzc/pythesis-plot.git ~/projects/pythesis-plot
ln -s ~/projects/pythesis-plot ~/.claude/skills/pythesis-plot
The verification section again uses a common, everyday request phrase as a trigger example, reinforcing auto-activation on generic plotting requests. In a multi-skill environment, this can lead to accidental routing, unnecessary file access, or unexpected behavior when users are making normal chart requests.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
In Claude Code, check if the skill is recognized:
ls ~/.claude/skills/pythesis-plot/SKILL.md
Should return the file path.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
In Claude Code, check if the skill is recognized:
ls ~/.claude/skills/pythesis-plot/SKILL.md
Should return the file path.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Fix:
mkdir -p ~/.claude/skills
cp -r pythesis-plot ~/.claude/skills/
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Fix: Check structure
ls -la ~/.claude/skills/pythesis-plot/
# Should see: SKILL.md, README.md, scripts/, assets/
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
Fix: Check structure
ls -la ~/.claude/skills/pythesis-plot/
# Should see: SKILL.md, README.md, scripts/, assets/
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux:
sudo apt-get install fonts-wqy-zenhei # Ubuntu/Debian
sudo yum install wqy-zenhei-fonts # CentOS/RHEL
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux:
sudo apt-get install fonts-wqy-zenhei # Ubuntu/Debian
sudo yum install wqy-zenhei-fonts # CentOS/RHEL
This markdown file presents the skill content entirely in Chinese and frames it as the canonical examples document, with no indication that users can choose another language. The policy for this audit flags language/locale constraints when a skill forces a specific language without user opt-in.
This markdown file contains user-facing guidance exclusively in Chinese and the example configuration explicitly sets Chinese fonts such as SimHei. Under the policy rule for language or locale constraints, this can be considered a forced language/locale experience because no opt-in, alternative language, or justification for a China-specific audience is provided.
This code file contains user-facing natural-language descriptions exclusively in Chinese, including the module docstring and later CLI/help/report text. The file does not offer any language selection or explain that the skill is intended only for a Chinese-speaking or region-specific context, which can violate language/locale policy requirements.
The manifest frames the skill as a scientific plotting tool that analyzes uploaded data and generates visualization recommendations/figures. This file also supports writing a standalone markdown-like analysis report to a user-specified filesystem path, which is an additional file-output behavior not described in the manifest and not necessary to merely recommend plots.
No suspicious patterns detected.