Back to skill

Security audit

Pythesis Plot

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed scientific plotting workflow, but it needs Review because its config-based plot generator can write files outside the intended output folder and it keeps local copies of uploaded data.

Install only if you are comfortable with a local plotting tool that reads your uploaded datasets and stores copies plus generated reports and figures on disk. Use a dedicated output folder, avoid running configs from untrusted sources, review generated plot_config.json before generation, and prefer a virtual environment with pinned dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/plot_generator.py:82
Finding

Configuration-Controlled Path Traversal Permits Figure Writes Outside the Output Directory

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
docs/installation.md:50
Finding

Unpinned Mutable Installation Sources Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
``` 2. Publish a lock file containing exact transitive dependency versions and hashes. 3. Install dependencies with hash enforcement: ```bash python -m pip install --require-hashes -r requirements.lock ``` 4. Require a dedicated virtual environment rather than describing it as merely optional. 5. Use `python -m pip` to ensure packages are installed into the intended interpreter. 6. Document the expected repository commit, release signature, package-index source, and integrity-verification procedure. 7. Add automated dependency scanning and controlled update review. Dependency revisions should be tested and audited before lock-file updates are published. 8. Avoid privileged package installation and explicitly warn users not to run the installation commands with `sudo` or as an administrative account. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · docs/installation.md (reported line 280)May include surrounding context.

If you need to remove the skill:

bash
rm -rf ~/.claude/skills/pythesis-plot

If using symlink, remove the link (not the original):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · docs/installation.md (reported line 280)May include surrounding context.

If you need to remove the skill:

bash
rm -rf ~/.claude/skills/pythesis-plot

If using symlink, remove the link (not the original):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · docs/installation.md (reported line 286)May include surrounding context.

If using symlink, remove the link (not the original):

bash
rm ~/.claude/skills/pythesis-plot  # Removes symlink only

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
## 🎯 What is PyThesisPlot?

PyThesisPlot is a **Claude Code Skill** that teaches AI assistants how to create publication-quality scientific figures from raw data. It provides:

- 📊 **Intelligent Workflow**: Data → Analysis → Recommendations → Confirmation → Figures
- 🎨 **Journal-Ready Output**: 300 DPI, Nature/Science style compliance

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented trigger is ambiguous about when the skill should activate, which creates unsafe uncertainty for downstream agents deciding whether to load it. Ambiguous activation is risky here because the skill is positioned to inspect uploaded data and create persistent outputs, so accidental invocation can expand data exposure beyond user expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger examples are broad enough to match ordinary requests for charts or figures, which can cause the skill to activate in situations the user did not specifically intend. In a skill that processes uploaded datasets and generates files, overbroad activation increases the chance of unexpected data handling and unintended execution of the plotting workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly shows that the original uploaded dataset is copied into a timestamped output directory, but it does not prominently warn users about this persistence behavior or its privacy implications. For research datasets, this can retain sensitive or regulated data in additional locations, increasing the risk of unintended disclosure, mishandling, or later exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger description includes broad phrases like asking for plotting or visualization around uploaded files, which can cause the skill to activate in unintended contexts. In a data-processing skill, overbroad activation increases the chance that sensitive user files are analyzed or persisted when the user did not explicitly intend to invoke this workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation states that the workflow saves a renamed copy of the raw dataset along with analysis artifacts and generated code, but it does not warn users about local persistence of potentially sensitive research or participant data. For thesis and scientific use cases, uploaded spreadsheets may contain personal, clinical, or unpublished data, so silent disk retention increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes file read/write behavior such as auto-saving uploaded files and generating reports, code, and images into output directories, but it does not declare any explicit tool scope or permissions. This creates an authorization and review gap: an agent or platform may grant broader filesystem access than users or reviewers expect, increasing the risk of unintended file access, overwrites, or data leakage if the implementation is looser than the documentation suggests.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

Telling users that they can now simply upload files and ask for charts encourages an always-ready usage pattern and may promote persistent expectation that the skill should activate on generic future requests. In agent environments, this can increase unintended reuse across sessions or tasks, especially when paired with broad trigger phrases.

Content

Scanner excerpt · docs/installation.md (reported line 95)May include surrounding context.

md
> ✅ PyThesisPlot skill installed successfully!
> 
> You can now upload data files and ask me to create charts.
> 
> Try: "Help me create figures from this CSV file"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installation guide explicitly tells users to test the skill with a very broad natural-language phrase, which increases the chance the skill will activate on ordinary plotting requests beyond the intended narrow context. Broad trigger guidance can cause unintended invocation and context capture, especially in agent ecosystems where activation is phrase-based.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/installation.md (reported line 138)May include surrounding context.

Clone to your projects folder

git clone https://github.com/stephenlzc/pythesis-plot.git ~/projects/pythesis-plot

Create symlink from Claude skills

ln -s ~/projects/pythesis-plot ~/.claude/skills/pythesis-plot

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The verification section again uses a common, everyday request phrase as a trigger example, reinforcing auto-activation on generic plotting requests. In a multi-skill environment, this can lead to accidental routing, unnecessary file access, or unexpected behavior when users are making normal chart requests.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/installation.md (reported line 159)May include surrounding context.

In Claude Code, check if the skill is recognized:

bash
ls ~/.claude/skills/pythesis-plot/SKILL.md

Should return the file path.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/installation.md (reported line 159)May include surrounding context.

In Claude Code, check if the skill is recognized:

bash
ls ~/.claude/skills/pythesis-plot/SKILL.md

Should return the file path.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/installation.md (reported line 189)May include surrounding context.

Fix:

bash
mkdir -p ~/.claude/skills
cp -r pythesis-plot ~/.claude/skills/

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/installation.md (reported line 208)May include surrounding context.

Fix: Check structure

bash
ls -la ~/.claude/skills/pythesis-plot/
# Should see: SKILL.md, README.md, scripts/, assets/

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · docs/installation.md (reported line 208)May include surrounding context.

Fix: Check structure

bash
ls -la ~/.claude/skills/pythesis-plot/
# Should see: SKILL.md, README.md, scripts/, assets/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/installation.md (reported line 225)May include surrounding context.

Linux:

bash
sudo apt-get install fonts-wqy-zenhei  # Ubuntu/Debian
sudo yum install wqy-zenhei-fonts      # CentOS/RHEL

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/installation.md (reported line 226)May include surrounding context.

Linux:

bash
sudo apt-get install fonts-wqy-zenhei  # Ubuntu/Debian
sudo yum install wqy-zenhei-fonts      # CentOS/RHEL

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents the skill content entirely in Chinese and frames it as the canonical examples document, with no indication that users can choose another language. The policy for this audit flags language/locale constraints when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese and the example configuration explicitly sets Chinese fonts such as SimHei. Under the policy rule for language or locale constraints, this can be considered a forced language/locale experience because no opt-in, alternative language, or justification for a China-specific audience is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing natural-language descriptions exclusively in Chinese, including the module docstring and later CLI/help/report text. The file does not offer any language selection or explain that the skill is intended only for a Chinese-speaking or region-specific context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the skill as a scientific plotting tool that analyzes uploaded data and generates visualization recommendations/figures. This file also supports writing a standalone markdown-like analysis report to a user-specified filesystem path, which is an additional file-output behavior not described in the manifest and not necessary to merely recommend plots.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.