Back to skill

Security audit

data-viz-wizard

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent CSV-to-chart tool, but its generated reports can execute unescaped CSV/title content and silently load remote JavaScript despite being described as standalone.

Review this before installing if you expect offline or self-contained reports, or if you may process CSV files from other people. Generated HTML should be treated as active web content, not a passive document, and should not be opened or hosted with sensitive data until the escaping issue and CDN dependency are fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/viz_wizard.py:996
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis

{chart_title}

""") html = html.replace('__CHART_SLOTS__', '\n'.join(slots)) ``` The chart configuration is inserted into an executable inline script: ```python html = html.replace('__CHARTS_JSON__', json.dumps(charts_config, default=str)) ``` A CSV-derived label is subsequently interpreted as HTML by the generated dashboard: ```javascript card.innerHTML = `
${label} — Sum
${fmt(total)}
`; ``` ### Technical Analysis User-controlled CLI titles, CSV headers, and C ...[truncated 2264 chars]
Remediation
View remediation
', '\\u003e') .replace('\u2028', '\\u2028') .replace('\u2029', '\\u2029') ) ``` 3. Prefer placing serialized data in a non-executable ``, ``, quotation marks, ampersands, and Unicode line separators. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/viz_wizard.py:479
Finding

Third-Party Chart.js Runtime Loaded Without Subresource Integrity

Content
View full analysis
``` The dashboard template uses the same remote dependency: ```html ``` ### Technical Analysis Every generated report downloads and executes JavaScript from jsDelivr when opened with network access. Although the Chart.js version is pinned to `4.4.7`, the script element does not include a Subresource Integrity hash. No restrictive Content Security Policy is included either. Consequently, the browser trusts the content returned by the CDN and executes it with full access to the report's page context. A compromised CDN, compromised upstream package artifact, or altered delivery path could therefore execute code capable of reading all chart data embedded in the report. This external runtime requirement also conflicts with the documentation's characterization of generated output as a complete standalone HTML file. ### Attack Path 1. A user generates a chart or dashboard. 2. The user opens the generated HTML while connected to a network. 3. The browser requests the pinned Chart.js resource from jsDelivr. 4. If the CDN response or corresponding package artifact has been maliciously altered, the browser accepts it because no integrity hash is specified. 5. The altered JavaScript executes in the generated report's page context. 6. The malicious dependency can read embedded chart data, alter the report, and attempt to transmit information over the network. ### Impact Assessment A compromised dependency would execute with the same browser privileges as the report itself. It could: - Read all dat ...[truncated 552 chars]
Remediation
View remediation
``` The integrity value must be generated from and verified against the exact production artifact rather than copied from an untrusted source. 3. Add a restrictive Content Security Policy that permits scripts only from explicitly approved sources. Remove inline scripts or protect them using nonces or verified hashes. 4. Document that opening a generated report may contact jsDelivr and that the embedded dataset is exposed to any JavaScript executing in the page. 5. Establish a dependency review and update process that verifies Chart.js releases and regenerates integrity hashes whenever the pinned version changes. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes commands that read CSV input and write generated HTML output, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates a mismatch between documented capabilities and declared restrictions, which can lead to overly broad or implicit file access at runtime and makes it harder for hosts to enforce least-privilege controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated HTML unconditionally loads Chart.js from a third-party CDN, which introduces outbound network access and a supply-chain dependency not inherent to local CSV-to-HTML conversion. Opening the output file can leak user metadata to the CDN and exposes users to tampering if the remote script is compromised or blocked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Loading executable JavaScript from a public CDN without any user-facing warning is a transparency and security problem: users may believe the output is a self-contained local file, but viewing it causes network requests and trusts third-party script delivery. In this skill context, that mismatch makes the issue more dangerous because users are handling local data and may not expect browser-side exfiltration paths.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The dashboard template also imports Chart.js from a public CDN, creating the same hidden network dependency and third-party code execution path as the single-chart output. This is especially relevant because the skill appears to promise local CSV transformation, while generated dashboards execute remote JavaScript when viewed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template sets , forcing an English locale in generated output without any user choice or documented justification. Under the language/locale policy, hard-coded language settings should not be imposed without opt-in or clear scope constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This dashboard template also sets , which enforces an English locale without offering users a choice. That creates the same natural-language locale policy concern as the single-chart template.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The tool performs file creation/overwrite via the --output path, including a default output filename, but the user-facing description does not warn that running the command will write an HTML file to disk. Although this is central to the tool's purpose, there is no explicit disclosure about overwrite/file-write behavior in the CLI description or usage text.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.