Back to skill

Security audit

观势 — 数据分析专家

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent data-analysis skill, but it tells the agent to automatically install unpinned Python packages into the current environment, which users should review before installing.

Install only if you are comfortable with the agent modifying the active Python environment. Prefer using a disposable virtual environment or preinstalling reviewed, pinned versions of pandas, numpy, scipy, and matplotlib before enabling the skill. Review outputs for locale assumptions if you need English or source-preserved labels.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:162
Finding

Automatic Installation of Unpinned Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 162
Vulnerability Type: Supply-chain risk from automatic, unpinned dependency installation
Risk Level: Medium

Vulnerable Code Snippet

markdown
### 依赖管理
- pandas / numpy / scipy / matplotlib 未安装时自动 `pip install`,安装到当前 Python 环境
- 图表中文字体缺失时降级为英文标签

The relevant instruction states that missing pandas, numpy, scipy, or matplotlib packages must be installed automatically with pip into the current Python environment.

Technical Analysis

The instruction does not specify exact package versions, integrity hashes, a trusted package index, an isolated virtual environment, or an approval step. Consequently, dependency resolution occurs dynamically at execution time and may install versions or transitive dependencies that were never reviewed with the Skill.

Python package installation can execute package-controlled build and installation logic. If the configured package repository, a package release, or a transitive dependency is compromised, malicious code could run with the privileges of the agent process. Installing directly into the current environment can also overwrite or alter dependencies used by unrelated workloads.

The named top-level packages are legitimate and there is no evidence in the project of deliberate dependency confusion or a malicious package source. The finding is therefore an unsafe supply-chain practice rather than proof of malicious intent.

Attack Path

  1. The Skill is invoked in an environment where one or more named packages are unavailable.
  2. Following line 162, the agent automatically executes an unpinned pip install.
  3. pip resolves the latest compatible top-level packages and transitive dependencies from its configured indexes.
  4. A compromised package release, dependency, or configured index supplies attacker-controlled installation content.
  5. Package build or installation logic executes under the agent process identity.
  6. The paylo ...[truncated 831 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic installation from normal Skill execution and fail safely with a clear list of missing dependencies.
  2. Require explicit user or administrator approval before modifying any Python environment.
  3. Define exact direct and transitive dependency versions in a reviewed lock file.
  4. Record and verify package hashes, using a command such as pip install --require-hashes -r requirements.txt.
  5. Restrict resolution to an approved HTTPS package index or an internally controlled package mirror.
  6. Install dependencies in a dedicated virtual environment or immutable container rather than the current shared environment.
  7. Prevent fallback to untrusted extra indexes and review package-index configuration before installation.
  8. Scan and periodically update locked dependencies through a controlled review process.
  9. Run installation and subsequent analysis with a least-privileged identity and restrict unnecessary network and filesystem access.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to unify mixed Chinese/English column names to Chinese first (or English) imposes a default language policy in the skill behavior. Because the file does not provide a user choice or opt-in for language/locale, this is a natural-language policy concern under the locale/language rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The chart specification explicitly requires Chinese fonts, which effectively forces a language/locale choice in generated outputs. Under the policy rule, mandatory locale-specific output should either be optional, user-selected, or clearly justified as a region-specific constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs automatic pip install into the current Python environment when dependencies are missing. Allowing a documentation-defined workflow to modify the runtime environment expands the skill from analysis into code/package execution and creates supply-chain and environment-integrity risk, especially if package sources, versions, or isolation are not tightly controlled.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A data-analysis skill does not need autonomous dependency installation to fulfill its purpose safely. This unjustified capability increases attack surface by permitting environment mutation and potential execution of unreviewed package install scripts, which can be abused or can destabilize the agent runtime.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

L169 presents the skill as handling source files in a read-only manner, conveying a constrained data-safety posture. But L170 documents writing intermediate results to a temp directory and final charts to output, which means the skill is not side-effect free with respect to the filesystem; the read-only claim is therefore materially incomplete and can mislead about actual write behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.