Back to skill

Security audit

Data Report Generator — CSV/Excel to Word/PDF with Charts

Security checks for vulnerabilities and agentic risk

Overview

The skill’s report-generation purpose is clear, but it asks the agent to modify the Python and OS environment and saves derived data files in fixed/shared locations.

Install or run this only in an isolated environment such as a virtualenv or container, avoid executing the --break-system-packages and apt-get commands on a shared machine, and review spreadsheet contents before use because generated charts and reports may retain sensitive data in output files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:111
Finding

Unsafe Runtime Dependency Installation and System-Level Package Modification

Content
View full analysis
/dev/null || true ``` From `references/pdf-fallback.md:5`: ```text Install: `pip install reportlab --break-system-packages` ``` ### Technical Analysis The Skill instructs the agent to install multiple third-party packages dynamically without exact version constraints or integrity hashes. As a result, the effective code installed during execution is mutable and may differ from the code that was reviewed. The `--break-system-packages` option explicitly bypasses Python's externally managed environment protection. This allows `pip` to install into or alter the host Python environment rather than requiring an isolated virtual environment. Such modification can overwrite distribution-managed packages, create incompatible dependency combinations, and affect unrelated applications that use the same interpreter. Python package installation can execute package build hooks and other installation-time code under the privileges of the invoking process. Consequently, compromise of a requested package, one of its transitive dependencies, the configured package index, or package-resolution infrastructure could result in arbitrary code execution. The `apt ...[truncated 2662 chars]
Remediation
View remediation
/dev/null || true`; fail safely and provide actionable error reporting. 10. Scan locked dependencies for known vulnerabilities and review lock-file changes before deployment. 11. Keep generated charts and reports in a dedicated, permission-restricted working directory rather than a shared system location. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (13)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The frontmatter description contains very broad trigger phrases such as general requests to analyze, summarize, visualize, or make reports from data files. Overbroad activation can cause the skill to run in situations the user did not clearly intend, increasing the chance of unnecessary file processing and generation of artifacts from sensitive spreadsheet contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill does not disclose that it writes generated reports to fixed local and shared output paths such as /home/claude/ and /mnt/user-data/outputs/. Users may reasonably expect transient analysis only, so silent persistence and copying of generated artifacts can create unintended data retention and exposure risks, especially for sensitive spreadsheets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill does not warn users that uploaded spreadsheet contents will be processed by Python libraries and may be copied into charts, summaries, and report files. Because this skill is specifically designed to ingest business datasets and reproduce their contents in new artifacts, lack of notice increases the risk of inadvertent propagation of confidential or regulated data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown activation section again uses ambiguous phrases like any mention of automated weekly/monthly reporting, which may trigger the skill for ordinary discussion rather than explicit execution requests. In this skill's context, mistaken activation means reading user-provided spreadsheets and creating documents, so the blast radius includes accidental handling of potentially confidential business data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to run apt-get install -y fonts-wqy-zenhei, which performs system-level package installation unrelated to the core need of analyzing tabular data and generating reports. Allowing a skill to modify the host environment expands attack surface, can fail unpredictably across environments, and normalizes privileged operations on behalf of untrusted user-triggered workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown includes a natural-language comment and configuration that prescribe CJK font support and hard-code a Chinese-oriented font preference order. This can violate language/locale policy because it imposes a specific locale setup without user opt-in or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The narrative template mixes Chinese and English headings and Chinese body text as the default output format without any indication that language should be selected based on user preference. In a reporting skill, this can cause unintended output, user confusion, and downstream business errors if reports are generated in a language the requester did not ask for.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to install a package with --break-system-packages, which can override Python environment protections and modify system-managed packages. In a skill intended for automated report generation, users may copy this command verbatim, increasing the risk of dependency conflicts, broken tooling, or unstable runtime environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown explicitly specifies "Executive Summary bullets (Chinese)", which imposes a language choice in the skill guidance. This is a natural-language policy concern because it directs output in a specific language without indicating that the user can choose or opt in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The narrative template and section headings explicitly prescribe bilingual or Chinese-language phrasing such as '最强正相关' and '## 变量分布' alongside English alternatives, but the file does not state that language should be selected based on user preference. This can violate language/locale policy because it nudges output into a specific language format without an explicit opt-in mechanism.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file provides code snippets that save multiple charts to local files via fig.savefig(...), which affects user data/workspace state. The surrounding documentation does not include any warning or note that running these examples will create or overwrite image files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains example code that saves chart images to local files using fig.savefig(...), which affects user data/system state by creating or overwriting files. The surrounding documentation does not include any warning or disclosure that running the examples will write PNG files to the working directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The guidance specifies the section heading as ## 趋势分析 or ## Trend Analysis, which constrains output language to Chinese or English without stating that the user should choose or be asked. This can conflict with language/locale policy expectations when the user's preferred language is different.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.