Back to skill

Security audit

Python Script Generator

Security checks for vulnerabilities and agentic risk

Overview

This appears to be an overstated and broken Python template generator rather than malware, but its broad claims, unsafe overwrite behavior, and dependency guidance need review before use.

Install only if you are comfortable reviewing and fixing the generator first. Run it in a disposable project directory, check for existing main.py or NAME.py files before use, pin any third-party dependencies in a virtual environment, and do not rely on the advertised Flask, Django, scraper, or bot support unless the implementation is updated.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:135
Finding

Unpinned Third-Party Dependency Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 135–145
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable code snippet:

bash
## 安装依赖

```bash
# CLI
pip install argparse

# FastAPI
pip install fastapi uvicorn

# Flask
pip install flask

# Scraper
pip install requests beautifulsoup4
text

### Technical Analysis

The installation instructions use mutable package names without exact versions, integrity hashes, a lock file, or a documented trusted package index. Consequently, installation results depend on whichever releases and package source are active when the commands are run.

The instruction to install `argparse` is unnecessary on supported Python 3 versions because `argparse` is included in the standard library. Installing an external package with that name needlessly increases supply-chain exposure.

This finding does not establish that the named packages are currently malicious. The weakness is that the documented process provides no controls against a future compromised release, unsafe index configuration, or dependency substitution.

### Attack Path

1. An attacker compromises a package release or gains influence over a package source available through the user's pip configuration.
2. The attacker publishes package content containing malicious installation or runtime behavior under a dependency name resolved by the documented commands.
3. A user follows the instructions in `SKILL.md` without a version lock or hash verification.
4. pip resolves and downloads the attacker-controlled or compromised release.
5. Malicious package behavior executes during installation or when the generated application imports and uses the dependency.

### Impact Assessment

Malicious dependency code would generally execute with the privileges of the user or automation account running pip or the generated application. Depending on that ac
...[truncated 396 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove pip install argparse; use Python 3's standard-library argparse module.
  2. Declare third-party dependencies in a maintained dependency manifest rather than relying solely on ad hoc installation commands.
  3. Pin reviewed versions exactly, for example with package==x.y.z.
  4. Generate and commit a lock file appropriate to the selected dependency-management tool.
  5. Require package hashes during reproducible installation, such as through a hash-locked requirements file and pip install --require-hashes.
  6. Document and enforce an approved package index rather than inheriting arbitrary user or CI index configuration.
  7. Add automated dependency vulnerability and integrity monitoring, with a controlled review process for upgrades.
  8. Recommend installation inside a dedicated virtual environment under a non-privileged account.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a broad Python project/template generator supporting multiple application types and complete project scaffolding. The supplied code only supports two minimal cases: a basic argparse CLI script and a minimal FastAPI app. It does not generate Flask, Django command, scraper, or comprehensive project templates. Additionally, the FastAPI branch writes to main.py but the script still chmods and reports NAME.py, showing behavior that is narrower and less consistent than the declared purpose. This is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language content of the skill, including its description and usage guidance, is presented only in Chinese. Under the stated policy, forcing a specific language without user opt-in or a documented locale justification is a language-policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description '生成 Python 脚本' is overly broad and does not clearly constrain when the skill should be invoked or what classes of Python code it is meant to generate. In an agent ecosystem, vague activation scope can cause the skill to be selected for unrelated requests, increasing the chance it generates or influences code in unsafe contexts without clear user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a skill that generates professional Python scripts and complete application templates across multiple frameworks, but this file only handles two minimal cases and, in the FastAPI branch, writes a hardcoded main.py while still reporting and chmod'ing $NAME.py. This is a semantic mismatch between the claimed generator behavior and the actual implemented operations for one supported type.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description mandates Python generation without indicating that this occurs only when the user explicitly wants Python output. This can steer an agent toward producing code in a specific language even when the user did not opt in, which is primarily a scoping and user-intent mismatch issue rather than a direct security exploit.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This shell script creates Python source files via redirection, but the only user-facing disclosure appears after generation completes. There is no comment, prompt, or prior notice indicating that running the skill will write files into the current directory, which matches the missing-warning criterion for code files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.