Back to skill

Security audit

Data Visualization

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent matplotlib chart-generation helper with no evidence of hidden execution, credential access, networking, persistence, or destructive behavior.

Install this if you want matplotlib report-style chart templates. Review or adjust generated output paths before running example scripts, and expect to change the hard-coded macOS font path if you are not on macOS or do not need Chinese labels.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description is written as operating in Chinese and the examples and guidance consistently assume Chinese-language usage, including Chinese font handling guidance later in the file. There is no statement that users may choose another language or locale, which can violate language-choice policy for general-purpose skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README includes a very broad invocation example ('帮我根据这张表自动选择合适图表并输出 matplotlib 代码') in a skill whose trigger keywords already cover generic charting terms. In an agent environment, this can cause the skill to activate for many ordinary data/plot requests, potentially overriding more appropriate tools or causing unintended routing behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description and keyword list are broad enough to activate this skill for many generic requests involving charts, plotting, or data graphics, even when the user did not specifically ask for this exact workflow. Over-broad activation can cause unintended routing, reducing user control and increasing the chance that the skill imposes its own constraints or style assumptions in unrelated contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill hard-codes Chinese language/font behavior and a macOS-specific system font path without checking the user's language preference, locale, or runtime environment. This can force undesired output language, break portability on non-macOS systems, and cause failures or degraded rendering when the font is unavailable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language strings and usage description are entirely in Chinese, and there is no indication that the skill is region-specific or that users may opt into another language/locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing chart text are written exclusively in Chinese, indicating a fixed language choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file contains user-facing natural-language text and comments in Chinese, including the module header and docstrings, without offering a language choice or documenting that the skill is intentionally region-specific. This can violate a language/locale policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The docstring and chart labeling instructions are written in Chinese and indicate a Chinese-localized presentation style, while the file does not provide any opt-in or alternative language choice. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains natural-language instructions that effectively force a specific language/locale context, including an explicit requirement for Chinese font handling. Under the policy, locale or language constraints should either be optional, user-selected, or clearly justified as region-specific; that opt-in or justification is not stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script writes an output image file via plt.savefig(...), which affects the local filesystem. There is no confirmation prompt, print/log message, or explanatory comment/docstring warning the user that running the script will create output_mckinsey_grouped_vbar.png.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This Python file performs a filesystem write by saving an image to output_mckinsey_stack100.png. There is no confirmation prompt, user-facing log/print statement, or explanatory warning in the file indicating that running it will create or overwrite a local file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document is written entirely in Chinese and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.